CVE-2022-50626Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.1%
top 80.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 8

Description

In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: fix memory leak in dvb_usb_adapter_init() Syzbot reports a memory leak in "dvb_usb_adapter_init()". The leak is due to not accounting for and freeing current iteration's adapter->priv in case of an error. Currently if an error occurs, it will exit before incrementing "num_adapters_initalized", which is used as a reference counter to free all adap->priv in "dvb_usb_adapter_exit()". There are multiple error paths

Affected Packages4 packages

Linuxlinux/linux_kernel2.6.194.9.337+7
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux4d43e13f723e12734257277cc38497fab1efc605733bc9e226da2a7f43b10031b8ebfc26d89ec4bd+9
debiandebian/linux< linux 6.1.4-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2022-50626: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: fix memory leak in dvb_usb_adapter_init() Syzbot reports a memory2025-12-08
OSV
media: dvb-usb: fix memory leak in dvb_usb_adapter_init()2025-12-08
GHSA
GHSA-9xm9-3332-24pq: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: fix memory leak in dvb_usb_adapter_init() Syzbot reports a memor2025-12-08

📋Vendor Advisories

2
Red Hat
kernel: media: dvb-usb: fix memory leak in dvb_usb_adapter_init()2025-12-08
Debian
CVE-2022-50626: linux - In the Linux kernel, the following vulnerability has been resolved: media: dvb-...2022