CVE-2022-50809Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: xhci: dbc: Fix memory leak in xhci_alloc_dbc() If DbC is already in use, then the allocated memory for the xhci_dbc struct doesn't get freed before returning NULL, which leads to a memleak.

Affected Packages4 packages

Linuxlinux/linux_kernel5.16.05.19.17+2
Debianlinux/linux_kernel< 6.0.3-1+2
CVEListV5linux/linuxd7afb4a13f6c6ee7df7d0bfc67b4ef19ece6d802103b459590e1eb4d80b02761eb36c7cae1d9b58e+4
debiandebian/linux< linux 6.0.3-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2022-50809: In the Linux kernel, the following vulnerability has been resolved: xhci: dbc: Fix memory leak in xhci_alloc_dbc() If DbC is already in use, then the2025-12-30
GHSA
GHSA-6ph6-qmh9-c936: In the Linux kernel, the following vulnerability has been resolved: xhci: dbc: Fix memory leak in xhci_alloc_dbc() If DbC is already in use, then th2025-12-30
OSV
xhci: dbc: Fix memory leak in xhci_alloc_dbc()2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel xHCI DbC: Denial of Service via memory leak2025-12-30
Debian
CVE-2022-50809: linux - In the Linux kernel, the following vulnerability has been resolved: xhci: dbc: ...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50809 Impact, Exploitability, and Mitigation Steps | Wiz