CVE-2022-50660Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 85.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ipw2200: fix memory leak in ipw_wdev_init() In the error path of ipw_wdev_init(), exception value is returned, and the memory applied for in the function is not released. Also the memory is not released in ipw_pci_probe(). As a result, memory leakage occurs. So memory release needs to be added to the error path of ipw_wdev_init().

Affected Packages4 packages

Linuxlinux/linux_kernel2.6.334.14.308+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxa3caa99e6c68f466c13cfea74097f6fb01b45e2575d20ba9506eb90d92e660e04dd887ff1495fcc3+8
debiandebian/linux< linux 6.1.20-1 (bookworm)

🔴Vulnerability Details

3
OSV
wifi: ipw2200: fix memory leak in ipw_wdev_init()2025-12-09
GHSA
GHSA-jjcv-w6qg-r3fw: In the Linux kernel, the following vulnerability has been resolved: wifi: ipw2200: fix memory leak in ipw_wdev_init() In the error path of ipw_wdev_2025-12-09
OSV
CVE-2022-50660: In the Linux kernel, the following vulnerability has been resolved: wifi: ipw2200: fix memory leak in ipw_wdev_init() In the error path of ipw_wdev_in2025-12-09

📋Vendor Advisories

2
Red Hat
kernel: wifi: ipw2200: fix memory leak in ipw_wdev_init()2025-12-09
Debian
CVE-2022-50660: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ipw22...2022