cbcvebase.
CVE-2022-50537
published 2025-10-07

CVE-2022-50537: In the Linux kernel, the following vulnerability has been resolved: firmware: raspberrypi: fix possible memory leak in rpi_firmware_probe() In…

PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: firmware: raspberrypi: fix possible memory leak in rpi_firmware_probe() In rpi_firmware_probe(), if mbox_request_channel() fails, the 'fw' will not be freed through rpi_firmware_delete(), fix this leak by calling kfree() in the error path.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 1e7c57355a3bc617fc220234889e49fe722a6305 < b308fdedef095aac14569f810d46edf773ea7d1eb308fdedef095aac14569f810d46edf773ea7d1e
linuxlinux>= 1e7c57355a3bc617fc220234889e49fe722a6305 < 6757dd2193fe18c5c5fe3050e7f2ff9dcbd1ff346757dd2193fe18c5c5fe3050e7f2ff9dcbd1ff34
linuxlinux>= 1e7c57355a3bc617fc220234889e49fe722a6305 < 71d2abab374f707ab8ac8dcef191fd2b3b67b8bd71d2abab374f707ab8ac8dcef191fd2b3b67b8bd
linuxlinux>= 1e7c57355a3bc617fc220234889e49fe722a6305 < 7b51161696e803fd5f9ad55b20a64c2df313f95c7b51161696e803fd5f9ad55b20a64c2df313f95c
linuxlinux>= 5.10.65 < 5.10.1635.10.163
linuxlinux>= 60831f5ae6c713afceb6d29f40899ed112f36059 < d34742245e4366579f9a80f8cfe4a63248e838e0d34742245e4366579f9a80f8cfe4a63248e838e0
linuxlinux>= d537afa08e156a0a72562e625506825c2776fcfa < 62ac943eb2a9d655e431b9bc98ff6d7bd51a0e4962ac943eb2a9d655e431b9bc98ff6d7bd51a0e49
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.10.65 < 5.10.1635.10.163
linuxlinux_kernel>= 5.13 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.