CVE-2022-50331

MEDIUM

Linux Kernel 5.14-5.14.75, 5.15.0-5.15.75, 5.16.0-6.0.5 - Use-After-Free in wwan_hwsim_dev_new()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: wwan_hwsim: fix possible memory leak in wwan_hwsim_dev_new() Inject fault while probing module, if device_register() fails, but the refcount of kobject is not decreased to 0, the name allocated in dev_set_name() is leaked. Fix this by calling put_device(), so that name can be freed in callback function kobject_cleanup(). unreferenced object 0xffff88810152ad20 (size 8): comm "modprobe", pid 252, jiffies 4294849206 (age 22.713s) hex dump (first 8 bytes): 68 77 73 69 6d 30 00 ff hwsim0.. backtrace: [<000000009c3504ed>] __kmalloc_node_track_caller+0x44/0x1b0 [<00000000c0228a5e>] kvasprintf+0xb5/0x140 [<00000000cff8c21f>] kvasprintf_const+0x55/0x180 [<0000000055a1e073>] kobject_set_name_vargs+0x56/0x150 [<000000000a80b139>] dev_set_name+0xab/0xe0

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (12)
linux/Kernel 5.14.0 - 5.15.76linux
linux/Kernel 5.16.0 - 6.0.6linux
Linux/Linux < 5.14
Linux/Linux 5.14
Linux/Linux 5.15.76 - 5.15.*
Linux/Linux 6.0.6 - 6.0.*
Linux/Linux 6.1
Linux/Linux f36a111a74e71edbba27d4c0cf3d7bbccc172108 - 258ad2fe5ede773625adfda88b173f4123e59f45
Linux/Linux f36a111a74e71edbba27d4c0cf3d7bbccc172108 - 50c31fa952309536c6e4461ff815ddccc8dff9d5
Linux/Linux f36a111a74e71edbba27d4c0cf3d7bbccc172108 - d87973314aba6de80a49f4271dd9be4ddc08e729
... and 2 more
Published Sep 15, 2025
Tracked Since Feb 18, 2026