CVE-2022-50360

MEDIUM

Linux Kernel 5.19-6.0.6 - Resource Leak via DRM DP Aux-Bus EP Lifetime Mismanagement

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: fix aux-bus EP lifetime Device-managed resources allocated post component bind must be tied to the lifetime of the aggregate DRM device or they will not necessarily be released when binding of the aggregate device is deferred. This can lead resource leaks or failure to bind the aggregate device when binding is later retried and a second attempt to allocate the resources is made. For the DP aux-bus, an attempt to populate the bus a second time will simply fail ("DP AUX EP device already populated"). Fix this by tying the lifetime of the EP device to the DRM device rather than DP controller platform device. Patchwork: https://patchwork.freedesktop.org/patch/502672/

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 6.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (9)
linux/Kernel 5.19.0 - 6.0.7linux
Linux/Linux < 5.19
Linux/Linux 5.19
Linux/Linux 6.0.7 - 6.0.*
Linux/Linux 6.1
Linux/Linux c3bf8e21b38a89418f2e22173b229aaad2306815 - 2b57f726611e294dc4297dd48eb8c98ef1938e82
Linux/Linux c3bf8e21b38a89418f2e22173b229aaad2306815 - 8768663188e4169333f66583e4d2432e65c421df
linux/linux_kernel 6.1 rc1 (2 CPE variants)
linux/linux_kernel 5.19 - 6.0.7
Published Sep 17, 2025
Tracked Since Feb 18, 2026