CVE-2022-50360

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-50360
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50360.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-50360
Downstream
Published
2025-09-17T15:15:34Z
Modified
2025-09-18T13:43:34Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/msm/dp: fix aux-bus EP lifetime

Device-managed resources allocated post component bind must be tied to the lifetime of the aggregate DRM device or they will not necessarily be released when binding of the aggregate device is deferred.

This can lead resource leaks or failure to bind the aggregate device when binding is later retried and a second attempt to allocate the resources is made.

For the DP aux-bus, an attempt to populate the bus a second time will simply fail ("DP AUX EP device already populated").

Fix this by tying the lifetime of the EP device to the DRM device rather than DP controller platform device.

Patchwork: https://patchwork.freedesktop.org/patch/502672/

References

Affected packages

Debian:12 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}