CVE-2022-50355

Source
https://cve.org/CVERecord?id=CVE-2022-50355
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50355.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-50355
Downstream
Related
Published
2025-09-17T14:56:08.356Z
Modified
2026-07-15T01:49:05.011458142Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
staging: vt6655: fix some erroneous memory clean-up loops
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: vt6655: fix some erroneous memory clean-up loops

In some initialization functions of this driver, memory is allocated with 'i' acting as an index variable and increasing from 0. The commit in "Fixes" introduces some clean-up codes in case of allocation failure, which free memory in reverse order with 'i' decreasing to 0. However, there are some problems: - The case i=0 is left out. Thus memory is leaked. - In case memory allocation fails right from the start, the memory freeing loops will start with i=-1 and invalid memory locations will be accessed.

One of these loops has been fixed in commit c8ff91535880 ("staging: vt6655: fix potential memory leak"). Fix the remaining erroneous loops.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50355.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5341ee0adb17d12a96dc5344e0d267cd12b52135
Fixed
637672a71f5016a40b0a6c0f3c8ad25eacedc8c3
Fixed
88b9cc60f26e8a05d1ddbddf91b09ca2915f20e0
Fixed
95ac62e8545be2b0a8cae0beef7c682e2e470e48
Fixed
f19e5b7df54590c831f350381963f25585c8f7d5
Fixed
a9e9806d1c315bc50dce05479a079b9a104474b8
Fixed
ed11b73c963292e7b49c0f37025c58ed3b7921d6
Fixed
2a2db520e3ca5aafba7c211abfd397666c9b5f9d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50355.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.18.0
Fixed
4.19.262
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.220
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.150
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.75
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.19.17
Type
ECOSYSTEM
Events
Introduced
5.20.0
Fixed
6.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50355.json"