CVE-2022-50836

UnknownEPSS 0.21%

Last modified

CVE-2022-50836 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev() The kfree() should be called when of_irq_get_byname() fails or devm_request_threaded_irq() fails in qcom_add_sysmon_subdev(), otherwise there will be a memory leak, so add kfree() to fix it.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev() The kfree() should be called when of_irq_get_byname() fails or devm_request_threaded_irq() fails in qcom_add_sysmon_subdev(), otherwise there will be a memory leak, so add kfree() to fix it.

Metrics

EPSS Probability
0.21%

11.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 027045a6e2b7cd81216e8a559534a30fb0782702, < 27441fab2651cd909d8a5440ca079bc50245f427; >= 027045a6e2b7cd81216e8a559534a30fb0782702, < e4539eb5c0c342567183fe386d0699c8dab49490; >= 027045a6e2b7cd81216e8a559534a30fb0782702, < 131c0a3ead78d45f0f39ddb42cf1bd9be26239b0; >= 027045a6e2b7cd81216e8a559534a30fb0782702, < 1a62bebe0705556d37cfa8409ddc759b11d404f6; >= 027045a6e2b7cd81216e8a559534a30fb0782702, < ec97e9a5c2f25d2f9f9d7005e9ac67f23cc751cd; >= 027045a6e2b7cd81216e8a559534a30fb0782702, < e01ce676aaef3b13d02343d7e70f9637d93a3367
LinuxLinux5.1

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50836?
In the Linux kernel, the following vulnerability has been resolved: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev() The kfree() should be called when of_irq_get_byname() fails or devm_request_threaded_irq() fails in qcom_add_sysmon_subdev(), otherwise there will be a memory leak, so add kfree() to fix it.
How severe is CVE-2022-50836?
Severity scoring for CVE-2022-50836 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50836?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50836?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST