CVE-2022-50250

MEDIUM

Linux Kernel < 4.19.270, 4.20.0-5.4.229, 5.5.0-5.15.86, 5.11.0-6.0.16, 5.16.0-6.1.2 - Use-After-Free in Regulator Core

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix use_count leakage when handling boot-on I found a use_count leakage towards supply regulator of rdev with boot-on option. ┌───────────────────┐ ┌───────────────────┐ │ regulator_dev A │ │ regulator_dev B │ │ (boot-on) │ │ (boot-on) │ │ use_count=0 │◀──supply──│ use_count=1 │ │ │ │ │ └───────────────────┘ └───────────────────┘ In case of rdev(A) configured with `regulator-boot-on', the use_count of supplying regulator(B) will increment inside regulator_enable(rdev->supply). Thus, B will acts like always-on, and further balanced regulator_enable/disable cannot actually disable it anymore. However, B was also configured with `regulator-boot-on', we wish it could be disabled afterwards.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (24)
linux/Kernel < 4.19.270linux
linux/Kernel 4.20.0 - 5.4.229linux
linux/Kernel 5.11.0 - 6.0.16linux
linux/Kernel 5.16.0 - 6.1.2linux
linux/Kernel 5.5.0 - 5.15.86linux
Linux/Linux < 5.5
Linux/Linux 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b - 0591b14ce0398125439c759f889647369aa616a0
Linux/Linux 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b - 4b737246ff50f810d6ab4be13c1388a07f0c14b1
Linux/Linux 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b - 4dd6e1cc9c7403f1ee1b7eee85bc31b797ae8347
Linux/Linux 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b - bc6c381df5793ebcf32db88a3e65acf7870379fc
... and 14 more
Published Sep 15, 2025
Tracked Since Feb 18, 2026