CVE-2022-50820
Last modified
CVE-2022-50820 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: perf/arm_dmc620: Fix hotplug callback leak in dmc620_pmu_init() dmc620_pmu_init() won't remove the callback added by cpuhp_setup_state_multi() when platform_driver_register() failed. Remove the callback by cpuhp_remove_multi_state() in fail path. Similar to the handling of arm_ccn_init() in commit 26242b330093 ("bus: arm-ccn: Prevent hotplug callback leak"). EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: perf/arm_dmc620: Fix hotplug callback leak in dmc620_pmu_init() dmc620_pmu_init() won't remove the callback added by cpuhp_setup_state_multi() when platform_driver_register() failed. Remove the callback by cpuhp_remove_multi_state() in fail path. Similar to the handling of arm_ccn_init() in commit 26242b330093 ("bus: arm-ccn: Prevent hotplug callback leak")
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 53c218da220c3619b5befec4674ffa35d590092a, < b99fbe8d949a99fe456f08c7aad421327685aa50; >= 53c218da220c3619b5befec4674ffa35d590092a, < af170afa97e50d4169cfaa7ff4ec5d3841182641; >= 53c218da220c3619b5befec4674ffa35d590092a, < adf7c3bbcc819db6e95b6a61c9822230f0ef4778; >= 53c218da220c3619b5befec4674ffa35d590092a, < d9f564c966e63925aac4ba273a9319d7fb6f4b4e |
| Linux | Linux | 5.11 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50820?
How severe is CVE-2022-50820?
How do I fix CVE-2022-50820?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50814In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50815In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50816In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50817In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50818In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50819In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50821In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50822In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50823In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50824In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50825In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50826In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50820?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
