CVE-2022-50566
Last modified
CVE-2022-50566 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: mtd: Fix device name leak when register device failed in add_mtd_device() There is a kmemleak when register device failed: unreferenced object 0xffff888101aab550 (size 8): comm "insmod", pid 3922, jiffies 4295277753 (age 925.408s) hex dump (first 8 bytes): 6d 74 64 30 00 88 ff ff mtd0.... backtrace: [<00000000bde26724>] __kmalloc_node_track_caller+0x4e/0x150 [<000000003c32b416>] kvasprintf+0xb0/0x130 [<000000001f7a8f15>] kobject_set_name_vargs+0x2f/0xb0 [<000000006e781163>] dev_set_name+0xab/0xe0 [<00000000e30d0c78>] add_mtd_device+0x4bb/0x700 [<00000000f3d34de7>] mtd_device_parse_register+0x2ac/0x3f0 [<00000000c0d88488>] 0xffffffffa0238457 [<00000000b40d0922>] 0xffffffffa02a008f [<0000000023d17b9d>] do_one_initcall+0x87/0x2a0 [<00000000770f6ca6>] do_init_module+0xdf/0x320 [<000000007b6768fe>] load_module+0x2f98/0x3330 [<00000000346bed5a>] __do_sys_finit_module+0x113/0x1b0 [<00000000674c2290>] do_syscall_64+0x35/0x80 [<000000004c6a8d97>] entry_SYSCALL_64_after_hwframe+0x46/0xb0 If register device failed, should call put_device() to give up the reference.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: mtd: Fix device name leak when register device failed in add_mtd_device() There is a kmemleak when register device failed: unreferenced object 0xffff888101aab550 (size 8): comm "insmod", pid 3922, jiffies 4295277753 (age 925.408s) hex dump (first 8 bytes): 6d 74 64 30 00 88 ff ff mtd0.... backtrace: [<00000000bde26724>] __kmalloc_node_track_caller+0x4e/0x150 [<000000003c32b416>] kvasprintf+0xb0/0x130 [<000000001f7a8f15>] kobject_set_name_vargs+0x2f/0xb0 [<000000006e781163>] dev_set_name+0xab/0xe0 [<00000000e30d0c78>] add_mtd_device+0x4bb/0x700 [<00000000f3d34de7>] mtd_device_parse_register+0x2ac/0x3f0 [<00000000c0d88488>] 0xffffffffa0238457 [<00000000b40d0922>] 0xffffffffa02a008f [<0000000023d17b9d>] do_one_initcall+0x87/0x2a0 [<00000000770f6ca6>] do_init_module+0xdf/0x320 [<000000007b6768fe>] load_module+0x2f98/0x3330 [<00000000346bed5a>] __do_sys_finit_module+0x113/0x1b0 [<00000000674c2290>] do_syscall_64+0x35/0x80 [<000000004c6a8d97>] entry_SYSCALL_64_after_hwframe+0x46/0xb0 If register device failed, should call put_device() to give up the reference.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < a75f45afa932bfb24a2603ebcea5efd2e7cdcfd6; >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < 2302e2dc42b1f84f951c725ce742fc21c5a1e151; >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < db07fe76df01f40cb897d6e9066b84e46957beb3; >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < fa0d32ab8407d7481450c664fd0de64f2dae9489; >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < 330bc5533e8a8ed69cb951d5a8edce9bddb9db21; >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < 71212d73184845c944ef1b43f092e643e5bde003; >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < 1b172fb05d6315ecec082fd7544a3390e96f0d7e; >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < bcabe1dc2a344adbb3382930a23e273ba9382277; >= 1f24b5a8ecbb2a3c7080f418974d40e3ffedb221, < 895d68a39481a75c680aa421546931fb11942fa6 |
| Linux | Linux | 2.6.30 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50566?
How severe is CVE-2022-50566?
How do I fix CVE-2022-50566?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50560In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50561In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50562In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50563In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50564In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50565In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50567In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50568In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50569In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50570In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50571In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50572In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50566?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
