CVE-2022-50734Linux vulnerability

7 documents6 sources
Severity
5.3MEDIUM
No vector
EPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: Fix memleak in nvmem_register() dev_set_name will alloc memory for nvmem->dev.kobj.name in nvmem_register, when nvmem_validate_keepouts failed, nvmem's memory will be freed and return, but nobody will free memory for nvmem->dev.kobj.name, there will be memleak, so moving nvmem_validate_keepouts() after device_register() and let the device core deal with cleaning name in error cases.

Affected Packages4 packages

Linuxlinux/linux_kernel5.15.05.15.75+2
Debianlinux/linux_kernel< 6.0.3-1+2
CVEListV5linux/linuxde0534df93474f268486c486ea7e01b44a4780269391cc3a787a58aa224a6440d7f244d780ba2896+6
debiandebian/linux< linux 6.0.3-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2022-50734: In the Linux kernel, the following vulnerability has been resolved: nvmem: core: Fix memleak in nvmem_register() dev_set_name will alloc memory for nv2025-12-24
OSV
nvmem: core: Fix memleak in nvmem_register()2025-12-24
GHSA
GHSA-p8g3-3wvp-3jxw: In the Linux kernel, the following vulnerability has been resolved: nvmem: core: Fix memleak in nvmem_register() dev_set_name will alloc memory for2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: nvmem: core: Fix memleak in nvmem_register()2025-12-24
Debian
CVE-2022-50734: linux - In the Linux kernel, the following vulnerability has been resolved: nvmem: core...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50734 Impact, Exploitability, and Mitigation Steps | Wiz