CVE-2022-50724
Last modified
CVE-2022-50724 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix resource leak in regulator_register() I got some resource leak reports while doing fault injection test: OF: ERROR: memory leak, expected refcount 1 instead of 100, of_node_get()/of_node_put() unbalanced - destroy cset entry: attach overlay node /i2c/pmic@64/regulators/buck1 unreferenced object 0xffff88810deea000 (size 512): comm "490-i2c-rt5190a", pid 253, jiffies 4294859840 (age 5061.046s) hex dump (first 32 bytes): 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N.......... ff ff ff ff ff ff ff ff a0 1e 00 a1 ff ff ff ff ................ backtrace: [<00000000d78541e2>] kmalloc_trace+0x21/0x110 [<00000000b343d153>] device_private_init+0x32/0xd0 [<00000000be1f0c70>] device_add+0xb2d/0x1030 [<00000000e3e6344d>] regulator_register+0xaf2/0x12a0 [<00000000e2f5e754>] devm_regulator_register+0x57/0xb0 [<000000008b898197>] rt5190a_probe+0x52a/0x861 [rt5190a_regulator] unreferenced object 0xffff88810b617b80 (size 32): comm "490-i2c-rt5190a", pid 253, jiffies 4294859904 (age 5060.983s) hex dump (first 32 bytes): 72 65 67 75 6c 61 74 6f 72 2e 32 38 36 38 2d 53 regulator.2868-S 55 50 50 4c 59 00 ff ff 29 00 00 00 2b 00 00 00 UPPLY...)...+... backtrace: [<000000009da9280d>] __kmalloc_node_track_caller+0x44/0x1b0 [<0000000025c6a4e5>] kstrdup+0x3a/0x70 [<00000000790efb69>] create_regulator+0xc0/0x4e0 [<0000000005ed203a>] regulator_resolve_supply+0x2d4/0x440 [<0000000045796214>] regulator_register+0x10b3/0x12a0 [<00000000e2f5e754>] devm_regulator_register+0x57/0xb0 [<000000008b898197>] rt5190a_probe+0x52a/0x861 [rt5190a_regulator] After calling regulator_resolve_supply(), the 'rdev->supply' is set by set_supply(), after this set, in the error path, the resources need be released, so call regulator_put() to avoid the leaks.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix resource leak in regulator_register() I got some resource leak reports while doing fault injection test: OF: ERROR: memory leak, expected refcount 1 instead of 100, of_node_get()/of_node_put() unbalanced - destroy cset entry: attach overlay node /i2c/pmic@64/regulators/buck1 unreferenced object 0xffff88810deea000 (size 512): comm "490-i2c-rt5190a", pid 253, jiffies 4294859840 (age 5061.046s) hex dump (first 32 bytes): 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N.......... ff ff ff ff ff ff ff ff a0 1e 00 a1 ff ff ff ff ................ backtrace: [<00000000d78541e2>] kmalloc_trace+0x21/0x110 [<00000000b343d153>] device_private_init+0x32/0xd0 [<00000000be1f0c70>] device_add+0xb2d/0x1030 [<00000000e3e6344d>] regulator_register+0xaf2/0x12a0 [<00000000e2f5e754>] devm_regulator_register+0x57/0xb0 [<000000008b898197>] rt5190a_probe+0x52a/0x861 [rt5190a_regulator] unreferenced object 0xffff88810b617b80 (size 32): comm "490-i2c-rt5190a", pid 253, jiffies 4294859904 (age 5060.983s) hex dump (first 32 bytes): 72 65 67 75 6c 61 74 6f 72 2e 32 38 36 38 2d 53 regulator.2868-S 55 50 50 4c 59 00 ff ff 29 00 00 00 2b 00 00 00 UPPLY...)...+... backtrace: [<000000009da9280d>] __kmalloc_node_track_caller+0x44/0x1b0 [<0000000025c6a4e5>] kstrdup+0x3a/0x70 [<00000000790efb69>] create_regulator+0xc0/0x4e0 [<0000000005ed203a>] regulator_resolve_supply+0x2d4/0x440 [<0000000045796214>] regulator_register+0x10b3/0x12a0 [<00000000e2f5e754>] devm_regulator_register+0x57/0xb0 [<000000008b898197>] rt5190a_probe+0x52a/0x861 [rt5190a_regulator] After calling regulator_resolve_supply(), the 'rdev->supply' is set by set_supply(), after this set, in the error path, the resources need be released, so call regulator_put() to avoid the leaks.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 0120ec32a7774b5061ced1a9a7ff833edd8b4cb6, < 35593d60b1622834984c43add7646d4069671aa9; >= aea6cb99703e17019e025aa71643b4d3e0a24413, < 6a03c31d08f95dca9633a552de167b9e625833a8; >= aea6cb99703e17019e025aa71643b4d3e0a24413, < c4c64d8abd656b9807b63178750fa91454602b86; >= aea6cb99703e17019e025aa71643b4d3e0a24413, < 90b713aadc1240bf2dd03d610d6c1d016a9123a2; >= aea6cb99703e17019e025aa71643b4d3e0a24413, < f86b2f216636790d5922458578825e4628fb570f; >= aea6cb99703e17019e025aa71643b4d3e0a24413, < ba62319a42c50e6254e98b3f316464fac8e77968; 1d58235c062309d51660fd04182d7a8ab6a48ad6; 167c3b1f9793a1fb23e75e693f078420850306d4; 3fc99e38fdbf6b693693f861aa55a50a74c2d202; 96c6b5d5775637b3095ef934f871044811fd4db7; f58ce31b05b4ca0c200a5cbe4724efe279405095; >= 5.4.73, < 5.4.229; >= 4.9.241, < 4.10; >= 4.14.203, < 4.15; >= 4.19.153, < 4.20; >= 5.8.17, < 5.9; >= 5.9.2, < 5.10 |
| Linux | Linux | 5.10 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50724?
How severe is CVE-2022-50724?
How do I fix CVE-2022-50724?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50718In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50719In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50720In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50721In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50722In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50723In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50725In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50726In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50727In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50728In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50729In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50730In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50724?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
