cbcvebase.
CVE-2022-50772
published 2025-12-24

CVE-2022-50772: In the Linux kernel, the following vulnerability has been resolved: netdevsim: fix memory leak in nsim_bus_dev_new() If device_register() failed in…

PriorityP419medium5.5
EPSS
0.21%
11.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netdevsim: fix memory leak in nsim_bus_dev_new() If device_register() failed in nsim_bus_dev_new(), the value of reference in nsim_bus_dev->dev is 1. obj->name in nsim_bus_dev->dev will not be released. unreferenced object 0xffff88810352c480 (size 16): comm "echo", pid 5691, jiffies 4294945921 (age 133.270s) hex dump (first 16 bytes): 6e 65 74 64 65 76 73 69 6d 31 00 00 00 00 00 00 netdevsim1...... backtrace: [] __kmalloc_node_track_caller+0x3a/0xb0 [] kvasprintf+0xc3/0x160 [] kvasprintf_const+0x55/0x180 [] kobject_set_name_vargs+0x56/0x150 [] dev_set_name+0xbb/0xf0 [] device_add+0x1f8/0x1cb0 [] new_device_store+0x3b6/0x5e0 [] bus_attr_store+0x72/0xa0 [] sysfs_kf_write+0x106/0x160 [] kernfs_fop_write_iter+0x3a8/0x5a0 [] vfs_write+0x8f0/0xc80 [] ksys_write+0x106/0x210 [] do_syscall_64+0x35/0x80 [] entry_SYSCALL_64_after_hwframe+0x46/0xb0

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.7-1 (bookworm)linux 6.0.7-1 (bookworm)
linuxlinux
linuxlinux>= 40e4fe4ce115c409c3e2fbb247085103ef1cc755 < 77579e4065295071fbd9662f03430dca5b50b08677579e4065295071fbd9662f03430dca5b50b086
linuxlinux>= 40e4fe4ce115c409c3e2fbb247085103ef1cc755 < cf2010aa1c739bab067cbc90b690d28eaa0b47dacf2010aa1c739bab067cbc90b690d28eaa0b47da
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 5.2.0 < 6.0.76.0.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.