cbcvebase.
CVE-2022-50672
published 2025-12-09

CVE-2022-50672: In the Linux kernel, the following vulnerability has been resolved: mailbox: zynq-ipi: fix error handling while device_register() fails If device_register()…

PriorityP422medium5.5
EPSS
0.22%
12.4th percentile
In the Linux kernel, the following vulnerability has been resolved: mailbox: zynq-ipi: fix error handling while device_register() fails If device_register() fails, it has two issues: 1. The name allocated by dev_set_name() is leaked. 2. The parent of device is not NULL, device_unregister() is called in zynqmp_ipi_free_mboxes(), it will lead a kernel crash because of removing not added device. Call put_device() to give up the reference, so the name is freed in kobject_cleanup(). Add device registered check in zynqmp_ipi_free_mboxes() to avoid null-ptr-deref.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < b3a5c76f61e2b380e29dfc6705854ca1ee85501db3a5c76f61e2b380e29dfc6705854ca1ee85501d
linuxlinux>= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < a39b4de0804f9fe0ae911b359ffd4afe7d9d933ba39b4de0804f9fe0ae911b359ffd4afe7d9d933b
linuxlinux>= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < 4f05d8e2fb3ab702c2633a74571e1b31cb5799854f05d8e2fb3ab702c2633a74571e1b31cb579985
linuxlinux>= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < f2d63cefc012cafe1b7651bbf3302f8bcd8bea4af2d63cefc012cafe1b7651bbf3302f8bcd8bea4a
linuxlinux>= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < 3fcf079958c00d83c51e4f250abf2c77fe9cc1b93fcf079958c00d83c51e4f250abf2c77fe9cc1b9
linuxlinux>= 4981b82ba2ff87df6a711fcd7a233c615df5fc79 < a6792a0cdef0b1c2d77920246283a72537e60e94a6792a0cdef0b1c2d77920246283a72537e60e94
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.1.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.