CVE-2022-50672

Linux Kernel - Use-After-Free in mailbox zynq-ipi device registration

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: mailbox: zynq-ipi: fix error handling while device_register() fails If device_register() fails, it has two issues: 1. The name allocated by dev_set_name() is leaked. 2. The parent of device is not NULL, device_unregister() is called in zynqmp_ipi_free_mboxes(), it will lead a kernel crash because of removing not added device. Call put_device() to give up the reference, so the name is freed in kobject_cleanup(). Add device registered check in zynqmp_ipi_free_mboxes() to avoid null-ptr-deref.

Scores

EPSS 0.0022
EPSS Percentile 12.4%

Details

Status published
Products (19)
linux/Kernel 5.1.0 - 5.4.229linux
linux/Kernel 5.11.0 - 5.15.86linux
linux/Kernel 5.16.0 - 6.0.16linux
linux/Kernel 5.5.0 - 5.10.163linux
linux/Kernel 6.1.0 - 6.1.2linux
Linux/Linux < 5.1
Linux/Linux 4981b82ba2ff87df6a711fcd7a233c615df5fc79 - 3fcf079958c00d83c51e4f250abf2c77fe9cc1b9
Linux/Linux 4981b82ba2ff87df6a711fcd7a233c615df5fc79 - 4f05d8e2fb3ab702c2633a74571e1b31cb579985
Linux/Linux 4981b82ba2ff87df6a711fcd7a233c615df5fc79 - a39b4de0804f9fe0ae911b359ffd4afe7d9d933b
Linux/Linux 4981b82ba2ff87df6a711fcd7a233c615df5fc79 - a6792a0cdef0b1c2d77920246283a72537e60e94
... and 9 more
Published Dec 09, 2025
Tracked Since Feb 18, 2026