cbcvebase.
CVE-2022-50624
published 2025-12-08

CVE-2022-50624: In the Linux kernel, the following vulnerability has been resolved: net: netsec: fix error handling in netsec_register_mdio() If phy_device_register() fails…

PriorityP420
EPSS
0.20%
10.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net: netsec: fix error handling in netsec_register_mdio() If phy_device_register() fails, phy_device_free() need be called to put refcount, so memory of phy device and device name can be freed in callback function. If get_phy_device() fails, mdiobus_unregister() need be called, or it will cause warning in mdiobus_free() and kobject is leaked.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.7-1 (bookworm)linux 6.0.7-1 (bookworm)
linuxlinux
linuxlinux>= 533dd11a12f698c571a12271b20f235792d3e148 < 728884b22d83148a330b23f9472f1e118b589211728884b22d83148a330b23f9472f1e118b589211
linuxlinux>= 533dd11a12f698c571a12271b20f235792d3e148 < fda2d07234a21be4d71ebfe97a45f499726902d6fda2d07234a21be4d71ebfe97a45f499726902d6
linuxlinux>= 533dd11a12f698c571a12271b20f235792d3e148 < 62f0a08e82a6312efd7df7f595c0b11d4ffde61062f0a08e82a6312efd7df7f595c0b11d4ffde610
linuxlinux>= 533dd11a12f698c571a12271b20f235792d3e148 < 1e0bee973ef6fc3c1e3acb014515eaea37c8fa171e0bee973ef6fc3c1e3acb014515eaea37c8fa17
linuxlinux>= 533dd11a12f698c571a12271b20f235792d3e148 < 846e677daf51220d7975c61a20e440a88473951e846e677daf51220d7975c61a20e440a88473951e
linuxlinux>= 533dd11a12f698c571a12271b20f235792d3e148 < 94423589689124e8cd145b38a1034be7f25835b294423589689124e8cd145b38a1034be7f25835b2
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 4.16.0 < 4.19.2644.19.264
linuxlinux_kernel>= 4.20.0 < 5.4.2235.4.223
linuxlinux_kernel>= 5.11.0 < 5.15.775.15.77
linuxlinux_kernel>= 5.16.0 < 6.0.76.0.7
linuxlinux_kernel>= 5.5.0 < 5.10.1535.10.153
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.