CVE-2022-50522

LOW

Linux kernel - Info Disclosure

Title source: llm

Description

In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount of bus and device name are leaked. Fix this by calling put_device() to give up the reference, so they can be released in mcb_release_dev() and kobject_cleanup().

Scores

CVSS v3 3.3
EPSS 0.0001
EPSS Percentile 1.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

Status draft

Affected Products (9)

linux/linux_kernel < 4.9.337
linux/Kernel < 4.9.337linux
linux/Kernel < 4.14.303linux
linux/Kernel < 4.19.270linux
linux/Kernel < 5.4.229linux
linux/Kernel < 5.10.163linux
linux/Kernel < 5.15.86linux
linux/Kernel < 6.0.16linux
linux/Kernel < 6.1.2linux

Timeline

Published Oct 07, 2025
Tracked Since Feb 18, 2026