CVE-2022-50658Missing Reference to Active Allocated Resource in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 90.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom: fix memory leak in error path If for some reason the speedbin length is incorrect, then there is a memory leak in the error path because we never free the speedbin buffer. This commit fixes the error path to always free the speedbin buffer.

Affected Packages4 packages

Linuxlinux/linux_kernel5.7.05.10.152+2
Debianlinux/linux_kernel< 5.10.158-1+3
CVEListV5linux/linuxa8811ec764f95a04ba82f6f457e28c5e9e36e36be55feb31df3fc78b880d6e9d4b5853f05c974833+4
debiandebian/linux< linux 6.0.6-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2022-50658: In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom: fix memory leak in error path If for some reason the speedbin lengt2025-12-09
GHSA
GHSA-8cxp-8frr-qhv6: In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom: fix memory leak in error path If for some reason the speedbin len2025-12-09
OSV
cpufreq: qcom: fix memory leak in error path2025-12-09

📋Vendor Advisories

2
Red Hat
kernel: cpufreq: qcom: fix memory leak in error path2025-12-09
Debian
CVE-2022-50658: linux - In the Linux kernel, the following vulnerability has been resolved: cpufreq: qc...2022