CVE-2022-50734
Last modified
CVE-2022-50734 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: nvmem: core: Fix memleak in nvmem_register() dev_set_name will alloc memory for nvmem->dev.kobj.name in nvmem_register, when nvmem_validate_keepouts failed, nvmem's memory will be freed and return, but nobody will free memory for nvmem->dev.kobj.name, there will be memleak, so moving nvmem_validate_keepouts() after device_register() and let the device core deal with cleaning name in error cases.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: nvmem: core: Fix memleak in nvmem_register() dev_set_name will alloc memory for nvmem->dev.kobj.name in nvmem_register, when nvmem_validate_keepouts failed, nvmem's memory will be freed and return, but nobody will free memory for nvmem->dev.kobj.name, there will be memleak, so moving nvmem_validate_keepouts() after device_register() and let the device core deal with cleaning name in error cases.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= de0534df93474f268486c486ea7e01b44a478026, < 9391cc3a787a58aa224a6440d7f244d780ba2896; >= de0534df93474f268486c486ea7e01b44a478026, < 2bd2774df0ce37920b23819a860a66fdbdd90823; >= de0534df93474f268486c486ea7e01b44a478026, < b6054b9b239a493672f853b034570cca93ba7a88; >= de0534df93474f268486c486ea7e01b44a478026, < bd1244561fa2a4531ded40dbf09c9599084f8b29; c1d44b93ca9f3ebc26b0de0a7f4b7156702762b6; 63c2b13ba0428b8f477e4adb1d40a50eb4493c09; >= 5.13.19, < 5.14; >= 5.14.6, < 5.15 |
| Linux | Linux | 5.15 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50734?
How severe is CVE-2022-50734?
How do I fix CVE-2022-50734?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50728In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50729In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50730In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50731In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50732In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2022-50733In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50735In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50736In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2022-50737In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50738In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50739In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50740In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50734?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
