CVE-2022-50537
MEDIUMLinux Kernel - Use-After-Free in Raspberry Pi Firmware Probe
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: firmware: raspberrypi: fix possible memory leak in rpi_firmware_probe() In rpi_firmware_probe(), if mbox_request_channel() fails, the 'fw' will not be freed through rpi_firmware_delete(), fix this leak by calling kfree() in the error path.
References (6)
Core 6
Core References
Scores
CVSS v3
5.5
EPSS
0.0014
EPSS Percentile
3.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-401
Status
published
Products (19)
linux/Kernel
< 5.10.163linux
linux/Kernel
5.11.0 - 5.15.86linux
linux/Kernel
5.13.0 - 6.0.16linux
linux/Kernel
5.16.0 - 6.1.2linux
Linux/Linux
< 5.13
Linux/Linux
1e7c57355a3bc617fc220234889e49fe722a6305 - 6757dd2193fe18c5c5fe3050e7f2ff9dcbd1ff34
Linux/Linux
1e7c57355a3bc617fc220234889e49fe722a6305 - 71d2abab374f707ab8ac8dcef191fd2b3b67b8bd
Linux/Linux
1e7c57355a3bc617fc220234889e49fe722a6305 - 7b51161696e803fd5f9ad55b20a64c2df313f95c
Linux/Linux
1e7c57355a3bc617fc220234889e49fe722a6305 - b308fdedef095aac14569f810d46edf773ea7d1e
Linux/Linux
5.10.163 - 5.10.*
... and 9 more
Published
Oct 07, 2025
Tracked Since
Feb 18, 2026