cbcvebase.
CVE-2022-50642
published 2025-12-09

CVE-2022-50642: In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_handles`…

PriorityP422medium5.5
EPSS
0.18%
7.5th percentile
In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_handles` allocates four pointers when obtaining type-c switch handles. These pointers are all freed if failing to obtain any of them; therefore, pointers in `port` become stale. The stale pointers eventually cause use-after-free or double free in later code paths. Zeroing out all pointer fields after freeing to eliminate these stale pointers.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= f28adb41dab4a2795fd959750df57adffd2bb0be < 0ceadb5a3e45f1b81cf54bd496b40a5e50b6bd400ceadb5a3e45f1b81cf54bd496b40a5e50b6bd40
linuxlinux>= f28adb41dab4a2795fd959750df57adffd2bb0be < b610758bb3e0674644c1255cdafc2f46b7e05ff9b610758bb3e0674644c1255cdafc2f46b7e05ff9
linuxlinux>= f28adb41dab4a2795fd959750df57adffd2bb0be < 6613f36a2fa5c69e528bccba8b3d831f759dad2f6613f36a2fa5c69e528bccba8b3d831f759dad2f
linuxlinux>= f28adb41dab4a2795fd959750df57adffd2bb0be < 9a8aadcf0b459c1257b9477fd6402e1d5952ae079a8aadcf0b459c1257b9477fd6402e1d5952ae07
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.9.0 < 5.15.865.15.86
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.