Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-50836

Опубликовано: 30 дек. 2025
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev() The kfree() should be called when of_irq_get_byname() fails or devm_request_threaded_irq() fails in qcom_add_sysmon_subdev(), otherwise there will be a memory leak, so add kfree() to fix it.

Отчет

A memory leak occurs in qcom_add_sysmon_subdev when the sysmon structure is allocated but not freed if shutdown irq lookup fails or if devm_request_threaded_irq fails. This can lead to gradual memory consumption if the code path is exercised repeatedly through repeated remoteproc bring up attempts or error recovery loops. The issue is local to the host system because it requires access to operations that instantiate the remoteproc sysmon subdevice. For the CVSS the PR is L because remote processor management is typically restricted to privileged users or system services. The security impact is primarily availability degradation over time rather than a direct crash or code execution primitive. Confidentiality and integrity impacts are not expected because the flaw is a straightforward leak.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2426102kernel: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev()

EPSS

Процентиль: 11%
0.00211
Низкий

3.3 Low

CVSS3

Связанные уязвимости

ubuntu
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev() The kfree() should be called when of_irq_get_byname() fails or devm_request_threaded_irq() fails in qcom_add_sysmon_subdev(), otherwise there will be a memory leak, so add kfree() to fix it.

nvd
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev() The kfree() should be called when of_irq_get_byname() fails or devm_request_threaded_irq() fails in qcom_add_sysmon_subdev(), otherwise there will be a memory leak, so add kfree() to fix it.

debian
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: r ...

github
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev() The kfree() should be called when of_irq_get_byname() fails or devm_request_threaded_irq() fails in qcom_add_sysmon_subdev(), otherwise there will be a memory leak, so add kfree() to fix it.

CVSS3: 5.5
fstec
больше 3 лет назад

Уязвимость функции qcom_add_sysmon_subdev() модуля drivers/remoteproc/qcom_sysmon.c драйвера подсистемы удаленного процессора ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 11%
0.00211
Низкий

3.3 Low

CVSS3