CVE-2022-50633

UnknownEPSS 0.17%

Last modified

CVE-2022-50633 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: qcom: Fix memory leak in dwc3_qcom_interconnect_init of_icc_get() alloc resources for path handle, we should release it when not need anymore. Like the release in dwc3_qcom_interconnect_exit() function. Add icc_put() in error handling to fix this.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: qcom: Fix memory leak in dwc3_qcom_interconnect_init of_icc_get() alloc resources for path handle, we should release it when not need anymore. Like the release in dwc3_qcom_interconnect_exit() function. Add icc_put() in error handling to fix this.

Metrics

EPSS Probability
0.17%

6.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= bea46b9815154ac47baf16b64022d791a4471375, < f9089b95548f0272e02a89989c511e235561d051; >= bea46b9815154ac47baf16b64022d791a4471375, < 56f6de394f0f57928cd401255a5c7866b68a77e3; >= bea46b9815154ac47baf16b64022d791a4471375, < 8c39c8d23ff9fb1beb6e16cf0ae929c764538625; >= bea46b9815154ac47baf16b64022d791a4471375, < 2f3b51189f7a7be5d822fb8c537d778c57eb9821; >= bea46b9815154ac47baf16b64022d791a4471375, < 97a48da1619ba6bd42a0e5da0a03aa490a9496b1
LinuxLinux5.10

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50633?
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: qcom: Fix memory leak in dwc3_qcom_interconnect_init of_icc_get() alloc resources for path handle, we should release it when not need anymore. Like the release in dwc3_qcom_interconnect_exit() function. Add icc_put() in error handling to fix this.
How severe is CVE-2022-50633?
Severity scoring for CVE-2022-50633 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50633?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50633?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST