Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2022-50355— staging: vt6655: fix some erroneous memory clean-up loops

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于内存清理循环错误,可能导致内存泄漏和无效内存访问。

CVSS 7.8 · High EPSS 0.22% · P12

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 5341ee0adb17d12a96dc5344e0d267cd12b52135< 637672a71f5016a40b0a6c0f3c8ad25eacedc8c3 affected
5341ee0adb17d12a96dc5344e0d267cd12b52135< 88b9cc60f26e8a05d1ddbddf91b09ca2915f20e0 affected
5341ee0adb17d12a96dc5344e0d267cd12b52135< 95ac62e8545be2b0a8cae0beef7c682e2e470e48 affected
5341ee0adb17d12a96dc5344e0d267cd12b52135< f19e5b7df54590c831f350381963f25585c8f7d5 affected
5341ee0adb17d12a96dc5344e0d267cd12b52135< a9e9806d1c315bc50dce05479a079b9a104474b8 affected
5341ee0adb17d12a96dc5344e0d267cd12b52135< ed11b73c963292e7b49c0f37025c58ed3b7921d6 affected
5341ee0adb17d12a96dc5344e0d267cd12b52135< 2a2db520e3ca5aafba7c211abfd397666c9b5f9d affected
4.18 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-50355

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
staging: vt6655: fix some erroneous memory clean-up loops
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: staging: vt6655: fix some erroneous memory clean-up loops In some initialization functions of this driver, memory is allocated with 'i' acting as an index variable and increasing from 0. The commit in "Fixes" introduces some clean-up codes in case of allocation failure, which free memory in reverse order with 'i' decreasing to 0. However, there are some problems: - The case i=0 is left out. Thus memory is leaked. - In case memory allocation fails right from the start, the memory freeing loops will start with i=-1 and invalid memory locations will be accessed. One of these loops has been fixed in commit c8ff91535880 ("staging: vt6655: fix potential memory leak"). Fix the remaining erroneous loops.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于内存清理循环错误,可能导致内存泄漏和无效内存访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 5341ee0adb17d12a96dc5344e0d267cd12b52135 ~ 637672a71f5016a40b0a6c0f3c8ad25eacedc8c3 -
Linux Linux 4.18 -

II. Public POCs for CVE-2022-50355

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-50355

请登录查看更多情报信息。

Same Patch Batch · Linux · 2025-09-17 · 56 CVEs total

CVE-2023-53338 9.8 CRITICAL lwt: Fix return values of BPF xmit ops
CVE-2022-50373 9.8 CRITICAL fs: dlm: fix race in lowcomms
CVE-2022-50363 9.8 CRITICAL skmsg: pass gfp argument to alloc_sk_msg()
CVE-2023-53360 9.8 CRITICAL NFSv4.2: Rework scratch handling for READ_PLUS (again)
CVE-2023-53358 8.8 HIGH ksmbd: fix racy issue under cocurrent smb2 tree disconnect
CVE-2023-53340 7.8 HIGH net/mlx5: Collect command failures data only for known commands
CVE-2022-50368 7.8 HIGH drm/msm/dsi: fix memory corruption with too many bridges
CVE-2022-50367 7.8 HIGH fs: fix UAF/GPF bug in nilfs_mdt_destroy
CVE-2022-50362 7.8 HIGH dmaengine: hisilicon: Add multi-thread support for a DMA channel
CVE-2023-53354 7.8 HIGH skbuff: skb_segment, Call zero copy functions before using skbuff frags
CVE-2022-50354 7.8 HIGH drm/amdkfd: Fix kfd_process_device_init_vm error handling
CVE-2022-50365 7.5 HIGH skbuff: Account for tail adjustment during pull operations
CVE-2023-53335 7.5 HIGH RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish()
CVE-2022-50374 Bluetooth: hci_{ldisc,serdev}: check percpu_init_rwsem() failure
CVE-2022-50353 mmc: wmt-sdmmc: fix return value check of mmc_add_host()
CVE-2023-53337 nilfs2: do not write dirty data after degenerating to read-only
CVE-2022-50356 net: sched: sfb: fix null pointer access issue when sfb_init() fails
CVE-2022-50372 cifs: Fix memory leak when build ntlmssp negotiate blob failed
CVE-2022-50371 led: qcom-lpg: Fix sleeping in atomic
CVE-2023-53336 media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings

Showing top 20 of 56 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-50355

No comments yet


Leave a comment