CVE-2022-50872Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: ARM: OMAP2+: Fix memory leak in realtime_counter_init() The "sys_clk" resource is malloced by clk_get(), it is not released when the function return.

Affected Packages4 packages

Linuxlinux/linux_kernel3.7.04.14.308+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxfa6d79d27614223d82418023b7f5300f1a1530d35f9aedabce3404dd8bb769822fc11317c55fbdc1+8
debiandebian/linux< linux 6.1.20-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2022-50872: In the Linux kernel, the following vulnerability has been resolved: ARM: OMAP2+: Fix memory leak in realtime_counter_init() The "sys_clk" resource is2025-12-30
GHSA
GHSA-76r8-fj78-cc7v: In the Linux kernel, the following vulnerability has been resolved: ARM: OMAP2+: Fix memory leak in realtime_counter_init() The "sys_clk" resource i2025-12-30
OSV
ARM: OMAP2+: Fix memory leak in realtime_counter_init()2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel (ARM OMAP2+): Memory leak in realtime_counter_init()2025-12-30
Debian
CVE-2022-50872: linux - In the Linux kernel, the following vulnerability has been resolved: ARM: OMAP2+...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50872 Impact, Exploitability, and Mitigation Steps | Wiz