cbcvebase.
CVE-2022-50544
published 2025-10-07

CVE-2022-50544: In the Linux kernel, the following vulnerability has been resolved: usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info()…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info() xhci_alloc_stream_info() allocates stream context array for stream_info ->stream_ctx_array with xhci_alloc_stream_ctx(). When some error occurs, stream_info->stream_ctx_array is not released, which will lead to a memory leak. We can fix it by releasing the stream_info->stream_ctx_array with xhci_free_stream_ctx() on the error path to avoid the potential memory leak.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < 7fc6bab3413e6a42bb1264ff7c9149808c93a4c77fc6bab3413e6a42bb1264ff7c9149808c93a4c7
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < e702de2f5c893bf2cdb0152191f99a6ad1411823e702de2f5c893bf2cdb0152191f99a6ad1411823
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < ddab9fe76296840aad686c66888a9c1dfdbff5ffddab9fe76296840aad686c66888a9c1dfdbff5ff
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < 9fa81cbd2dd300aa8fe9bac70e068b9a11cbb1449fa81cbd2dd300aa8fe9bac70e068b9a11cbb144
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < 91271a3e772e180bbb8afb114c72fd294a02f93d91271a3e772e180bbb8afb114c72fd294a02f93d
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < fcd594da0b5955119d9707e4e0a8d0fb1c969101fcd594da0b5955119d9707e4e0a8d0fb1c969101
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < a40ad475236022f3432880e3091c380e46e71a71a40ad475236022f3432880e3091c380e46e71a71
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < 782c873f8e7686f5b3c47e8b099f7e08c3dd1fdc782c873f8e7686f5b3c47e8b099f7e08c3dd1fdc
linuxlinux>= 8df75f42f8e67e2851cdcf6da91640fb881defd1 < 7e271f42a5cc3768cd2622b929ba66859ae21f977e271f42a5cc3768cd2622b929ba66859ae21f97
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 2.6.35 < 4.9.3314.9.331
linuxlinux_kernel>= 4.10 < 4.14.2964.14.296
linuxlinux_kernel>= 4.15 < 4.19.2624.19.262
linuxlinux_kernel>= 4.20 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.