CVE-2022-50882Missing Release of Resource after Effective Lifetime in Linux

Severity
3.3LOW
No vector
EPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix memory leak in uvc_gpio_parse Previously the unit buffer was allocated before checking the IRQ for privacy GPIO. In case of error, the unit buffer was leaked. Allocate the unit buffer after the IRQ to avoid it. Addresses-Coverity-ID: 1474639 ("Resource leak")

Affected Packages4 packages

Linuxlinux/linux_kernel5.12.05.15.75+2
Debianlinux/linux_kernel< 6.0.3-1+2
CVEListV5linux/linux2886477ff98740cc3333cf785e4de0b1ff3d7a286c5da92103bddd1f0c36cb69446ff7cae3043986+4
debiandebian/linux< linux 6.0.3-1 (bookworm)

🔴Vulnerability Details

3
OSV
media: uvcvideo: Fix memory leak in uvc_gpio_parse2025-12-30
GHSA
GHSA-7rr3-6945-h32g: In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix memory leak in uvc_gpio_parse Previously the unit buffer wa2025-12-30
OSV
CVE-2022-50882: In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix memory leak in uvc_gpio_parse Previously the unit buffer was2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: media: uvcvideo: Fix memory leak in uvc_gpio_parse2025-12-30
Debian
CVE-2022-50882: linux - In the Linux kernel, the following vulnerability has been resolved: media: uvcv...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50882 Impact, Exploitability, and Mitigation Steps | Wiz