CVE-2022-50672
published 2025-12-09CVE-2022-50672: In the Linux kernel, the following vulnerability has been resolved: mailbox: zynq-ipi: fix error handling while device_register() fails If device_register()…
PriorityP422medium5.5
EPSS
0.22%
12.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
mailbox: zynq-ipi: fix error handling while device_register() fails
If device_register() fails, it has two issues:
1. The name allocated by dev_set_name() is leaked.
2. The parent of device is not NULL, device_unregister() is called
in zynqmp_ipi_free_mboxes(), it will lead a kernel crash because
of removing not added device.
Call put_device() to give up the reference, so the name is freed in
kobject_cleanup(). Add device registered check in zynqmp_ipi_free_mboxes()
to avoid null-ptr-deref.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < b3a5c76f61e2b380e29dfc6705854ca1ee85501d | b3a5c76f61e2b380e29dfc6705854ca1ee85501d |
| linux | linux | >= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < a39b4de0804f9fe0ae911b359ffd4afe7d9d933b | a39b4de0804f9fe0ae911b359ffd4afe7d9d933b |
| linux | linux | >= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < 4f05d8e2fb3ab702c2633a74571e1b31cb579985 | 4f05d8e2fb3ab702c2633a74571e1b31cb579985 |
| linux | linux | >= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < f2d63cefc012cafe1b7651bbf3302f8bcd8bea4a | f2d63cefc012cafe1b7651bbf3302f8bcd8bea4a |
| linux | linux | >= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < 3fcf079958c00d83c51e4f250abf2c77fe9cc1b9 | 3fcf079958c00d83c51e4f250abf2c77fe9cc1b9 |
| linux | linux | >= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < a6792a0cdef0b1c2d77920246283a72537e60e94 | a6792a0cdef0b1c2d77920246283a72537e60e94 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 5.1.0 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.11.0 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16.0 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.5.0 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1.0 < 6.1.2 | 6.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: mailbox: zynq-ipi: fix error handling while device_register() fails
vendor_redhat·2025-12-09·CVSS 5.5
CVE-2022-50672 [MEDIUM] CWE-253 kernel: mailbox: zynq-ipi: fix error handling while device_register() fails
kernel: mailbox: zynq-ipi: fix error handling while device_register() fails
In the Linux kernel, the following vulnerability has been resolved:
mailbox: zynq-ipi: fix error handling while device_register() fails
If device_register() fails, it has two issues:
1. The name allocated by dev_set_name() is leaked.
2. The parent of device is not NULL, device_unregister() is called
in zynqmp_ipi_free_mboxes(), it will lead a kernel crash because
of removing not added device.
Call put_device() to give up the reference, so the name is freed in
kobject_cleanup(). Add device registered check in zynqmp_ipi_free_mboxes()
to avoid null-ptr-deref.
A vulnerability was found in the Xilinx ZynqMP IPI mailbox driver in the Linux kernel. When device_register() fails, two issues occur: the name allocated by d
Debian
CVE-2022-50672: linux - In the Linux kernel, the following vulnerability has been resolved: mailbox: zy...
vendor_debian·2022
CVE-2022-50672 CVE-2022-50672: linux - In the Linux kernel, the following vulnerability has been resolved: mailbox: zy...
In the Linux kernel, the following vulnerability has been resolved: mailbox: zynq-ipi: fix error handling while device_register() fails If device_register() fails, it has two issues: 1. The name allocated by dev_set_name() is leaked. 2. The parent of device is not NULL, device_unregister() is called in zynqmp_ipi_free_mboxes(), it will lead a kernel crash because of removing not added device. Call put_device() to give up the reference, so the name is freed in kobject_cleanup(). Add device registered check in zynqmp_ipi_free_mboxes() to avoid null-ptr-deref.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
OSV
CVE-2022-50672: In the Linux kernel, the following vulnerability has been resolved: mailbox: zynq-ipi: fix error handling while device_register() fails If device_regi
osv·2025-12-09
CVE-2022-50672 CVE-2022-50672: In the Linux kernel, the following vulnerability has been resolved: mailbox: zynq-ipi: fix error handling while device_register() fails If device_regi
In the Linux kernel, the following vulnerability has been resolved: mailbox: zynq-ipi: fix error handling while device_register() fails If device_register() fails, it has two issues: 1. The name allocated by dev_set_name() is leaked. 2. The parent of device is not NULL, device_unregister() is called in zynqmp_ipi_free_mboxes(), it will lead a kernel crash because of removing not added device. Call put_device() to give up the reference, so the name is freed in kobject_cleanup(). Add device registered check in zynqmp_ipi_free_mboxes() to avoid null-ptr-deref.
GHSA
GHSA-fc53-63px-vp2j: In the Linux kernel, the following vulnerability has been resolved:
mailbox: zynq-ipi: fix error handling while device_register() fails
If device_re
ghsa_unreviewed·2025-12-09
CVE-2022-50672 GHSA-fc53-63px-vp2j: In the Linux kernel, the following vulnerability has been resolved:
mailbox: zynq-ipi: fix error handling while device_register() fails
If device_re
In the Linux kernel, the following vulnerability has been resolved:
mailbox: zynq-ipi: fix error handling while device_register() fails
If device_register() fails, it has two issues:
1. The name allocated by dev_set_name() is leaked.
2. The parent of device is not NULL, device_unregister() is called
in zynqmp_ipi_free_mboxes(), it will lead a kernel crash because
of removing not added device.
Call put_device() to give up the reference, so the name is freed in
kobject_cleanup(). Add device registered check in zynqmp_ipi_free_mboxes()
to avoid null-ptr-deref.
OSV
mailbox: zynq-ipi: fix error handling while device_register() fails
osv·2025-12-09
CVE-2022-50672 mailbox: zynq-ipi: fix error handling while device_register() fails
mailbox: zynq-ipi: fix error handling while device_register() fails
In the Linux kernel, the following vulnerability has been resolved:
mailbox: zynq-ipi: fix error handling while device_register() fails
If device_register() fails, it has two issues:
1. The name allocated by dev_set_name() is leaked.
2. The parent of device is not NULL, device_unregister() is called
in zynqmp_ipi_free_mboxes(), it will lead a kernel crash because
of removing not added device.
Call put_device() to give up the reference, so the name is freed in
kobject_cleanup(). Add device registered check in zynqmp_ipi_free_mboxes()
to avoid null-ptr-deref.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3fcf079958c00d83c51e4f250abf2c77fe9cc1b9https://git.kernel.org/stable/c/4f05d8e2fb3ab702c2633a74571e1b31cb579985https://git.kernel.org/stable/c/a39b4de0804f9fe0ae911b359ffd4afe7d9d933bhttps://git.kernel.org/stable/c/a6792a0cdef0b1c2d77920246283a72537e60e94https://git.kernel.org/stable/c/b3a5c76f61e2b380e29dfc6705854ca1ee85501dhttps://git.kernel.org/stable/c/f2d63cefc012cafe1b7651bbf3302f8bcd8bea4a
2025-12-09
Published