cbcvebase.
CVE-2022-50562
published 2025-10-22

CVE-2022-50562: In the Linux kernel, the following vulnerability has been resolved: tpm: acpi: Call acpi_put_table() to fix memory leak The start and length of the event log…

PriorityP418low5.5
EPSS
0.20%
10.0th percentile
In the Linux kernel, the following vulnerability has been resolved: tpm: acpi: Call acpi_put_table() to fix memory leak The start and length of the event log area are obtained from TPM2 or TCPA table, so we call acpi_get_table() to get the ACPI information, but the acpi_get_table() should be coupled with acpi_put_table() to release the ACPI memory, add the acpi_put_table() properly to fix the memory leak. While we are at it, remove the redundant empty line at the end of the tpm_read_log_acpi().

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 0bfb23746052168620c5b52f49d8a47c3bb022fa < 8ddc48068ac85740d3d5f9f3b0b323e733a35b338ddc48068ac85740d3d5f9f3b0b323e733a35b33
linuxlinux>= 0bfb23746052168620c5b52f49d8a47c3bb022fa < 638cd298dfebce46919cbd6cf1884701215f506d638cd298dfebce46919cbd6cf1884701215f506d
linuxlinux>= 0bfb23746052168620c5b52f49d8a47c3bb022fa < 694a3d66f493afd77c704c6de91d9be4d6e004e4694a3d66f493afd77c704c6de91d9be4d6e004e4
linuxlinux>= 0bfb23746052168620c5b52f49d8a47c3bb022fa < bf31e3f8077af539feaf4e9bbf82e8eb51e7e5a8bf31e3f8077af539feaf4e9bbf82e8eb51e7e5a8
linuxlinux>= 0bfb23746052168620c5b52f49d8a47c3bb022fa < 8740a12ca2e2959531ad253bac99ada338b33d808740a12ca2e2959531ad253bac99ada338b33d80
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.18.0 < 5.10.1635.10.163
linuxlinux_kernel>= 5.11.0 < 5.15.875.15.87
linuxlinux_kernel>= 5.16.0 < 6.0.176.0.17
linuxlinux_kernel>= 6.1.0 < 6.1.36.1.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.