CVE-2022-50642
published 2025-12-09CVE-2022-50642: In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_handles`…
PriorityP422medium5.5
EPSS
0.18%
7.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
platform/chrome: cros_ec_typec: zero out stale pointers
`cros_typec_get_switch_handles` allocates four pointers when obtaining
type-c switch handles. These pointers are all freed if failing to obtain
any of them; therefore, pointers in `port` become stale. The stale
pointers eventually cause use-after-free or double free in later code
paths. Zeroing out all pointer fields after freeing to eliminate these
stale pointers.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= f28adb41dab4a2795fd959750df57adffd2bb0be < 0ceadb5a3e45f1b81cf54bd496b40a5e50b6bd40 | 0ceadb5a3e45f1b81cf54bd496b40a5e50b6bd40 |
| linux | linux | >= f28adb41dab4a2795fd959750df57adffd2bb0be < b610758bb3e0674644c1255cdafc2f46b7e05ff9 | b610758bb3e0674644c1255cdafc2f46b7e05ff9 |
| linux | linux | >= f28adb41dab4a2795fd959750df57adffd2bb0be < 6613f36a2fa5c69e528bccba8b3d831f759dad2f | 6613f36a2fa5c69e528bccba8b3d831f759dad2f |
| linux | linux | >= f28adb41dab4a2795fd959750df57adffd2bb0be < 9a8aadcf0b459c1257b9477fd6402e1d5952ae07 | 9a8aadcf0b459c1257b9477fd6402e1d5952ae07 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 5.16.0 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.9.0 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 6.1.0 < 6.1.2 | 6.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: platform/chrome: cros_ec_typec: zero out stale pointers
vendor_redhat·2025-12-09·CVSS 5.5
CVE-2022-50642 [MEDIUM] CWE-825 kernel: platform/chrome: cros_ec_typec: zero out stale pointers
kernel: platform/chrome: cros_ec_typec: zero out stale pointers
In the Linux kernel, the following vulnerability has been resolved:
platform/chrome: cros_ec_typec: zero out stale pointers
`cros_typec_get_switch_handles` allocates four pointers when obtaining
type-c switch handles. These pointers are all freed if failing to obtain
any of them; therefore, pointers in `port` become stale. The stale
pointers eventually cause use-after-free or double free in later code
paths. Zeroing out all pointer fields after freeing to eliminate these
stale pointers.
A use-after-free vulnerability exists in the Chrome EC Type-C driver in the Linux kernel. When cros_typec_get_switch_handles() fails to obtain switch handles, it frees allocated pointers but doesn't zero them out. These stale pointers can lat
Debian
CVE-2022-50642: linux - In the Linux kernel, the following vulnerability has been resolved: platform/ch...
vendor_debian·2022
CVE-2022-50642 CVE-2022-50642: linux - In the Linux kernel, the following vulnerability has been resolved: platform/ch...
In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_handles` allocates four pointers when obtaining type-c switch handles. These pointers are all freed if failing to obtain any of them; therefore, pointers in `port` become stale. The stale pointers eventually cause use-after-free or double free in later code paths. Zeroing out all pointer fields after freeing to eliminate these stale pointers.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: open
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
OSV
CVE-2022-50642: In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_han
osv·2025-12-09
CVE-2022-50642 CVE-2022-50642: In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_han
In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_handles` allocates four pointers when obtaining type-c switch handles. These pointers are all freed if failing to obtain any of them; therefore, pointers in `port` become stale. The stale pointers eventually cause use-after-free or double free in later code paths. Zeroing out all pointer fields after freeing to eliminate these stale pointers.
OSV
platform/chrome: cros_ec_typec: zero out stale pointers
osv·2025-12-09
CVE-2022-50642 platform/chrome: cros_ec_typec: zero out stale pointers
platform/chrome: cros_ec_typec: zero out stale pointers
In the Linux kernel, the following vulnerability has been resolved:
platform/chrome: cros_ec_typec: zero out stale pointers
`cros_typec_get_switch_handles` allocates four pointers when obtaining
type-c switch handles. These pointers are all freed if failing to obtain
any of them; therefore, pointers in `port` become stale. The stale
pointers eventually cause use-after-free or double free in later code
paths. Zeroing out all pointer fields after freeing to eliminate these
stale pointers.
GHSA
GHSA-hcmx-x6wc-rr97: In the Linux kernel, the following vulnerability has been resolved:
platform/chrome: cros_ec_typec: zero out stale pointers
`cros_typec_get_switch_h
ghsa_unreviewed·2025-12-09
CVE-2022-50642 GHSA-hcmx-x6wc-rr97: In the Linux kernel, the following vulnerability has been resolved:
platform/chrome: cros_ec_typec: zero out stale pointers
`cros_typec_get_switch_h
In the Linux kernel, the following vulnerability has been resolved:
platform/chrome: cros_ec_typec: zero out stale pointers
`cros_typec_get_switch_handles` allocates four pointers when obtaining
type-c switch handles. These pointers are all freed if failing to obtain
any of them; therefore, pointers in `port` become stale. The stale
pointers eventually cause use-after-free or double free in later code
paths. Zeroing out all pointer fields after freeing to eliminate these
stale pointers.
No detection rules found.
No public exploits indexed.
2025-12-09
Published