Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-50544— usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于xhci_alloc_stream_info函数错误路径未释放stream_ctx_array,可能导致内存泄漏。

AI Predicted 5.0 Difficulty: Moderate EPSS 0.15% · P5

Possible ATT&CK Techniques 1 AI

T1564.004 · NTFS File Attributes

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux 8df75f42f8e67e2851cdcf6da91640fb881defd1< 7fc6bab3413e6a42bb1264ff7c9149808c93a4c7 affected
8df75f42f8e67e2851cdcf6da91640fb881defd1< e702de2f5c893bf2cdb0152191f99a6ad1411823 affected
8df75f42f8e67e2851cdcf6da91640fb881defd1< ddab9fe76296840aad686c66888a9c1dfdbff5ff affected
8df75f42f8e67e2851cdcf6da91640fb881defd1< 9fa81cbd2dd300aa8fe9bac70e068b9a11cbb144 affected
8df75f42f8e67e2851cdcf6da91640fb881defd1< 91271a3e772e180bbb8afb114c72fd294a02f93d affected
8df75f42f8e67e2851cdcf6da91640fb881defd1< fcd594da0b5955119d9707e4e0a8d0fb1c969101 affected
8df75f42f8e67e2851cdcf6da91640fb881defd1< a40ad475236022f3432880e3091c380e46e71a71 affected
8df75f42f8e67e2851cdcf6da91640fb881defd1< 782c873f8e7686f5b3c47e8b099f7e08c3dd1fdc affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-50544

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info() xhci_alloc_stream_info() allocates stream context array for stream_info ->stream_ctx_array with xhci_alloc_stream_ctx(). When some error occurs, stream_info->stream_ctx_array is not released, which will lead to a memory leak. We can fix it by releasing the stream_info->stream_ctx_array with xhci_free_stream_ctx() on the error path to avoid the potential memory leak.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于xhci_alloc_stream_info函数错误路径未释放stream_ctx_array,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 8df75f42f8e67e2851cdcf6da91640fb881defd1 ~ 7fc6bab3413e6a42bb1264ff7c9149808c93a4c7 -
Linux Linux 2.6.35 -

II. Public POCs for CVE-2022-50544

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-50544

登录查看更多情报信息。

Patches & Fixes for CVE-2022-50544 (9)

Same Patch Batch · Linux · 2025-10-07 · 118 CVEs total

CVE-2023-53629 9.8 CRITICAL fs: dlm: fix use after free in midcomms commit
CVE-2023-53630 8.8 HIGH iommufd: Fix unpinning of pages when an access is present
CVE-2023-53676 8.8 HIGH scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show()
CVE-2023-53675 8.8 HIGH scsi: ses: Fix possible desc_ptr out-of-bounds accesses
CVE-2023-53673 8.8 HIGH Bluetooth: hci_event: call disconnect callback before deleting conn
CVE-2023-53679 8.3 HIGH wifi: mt7601u: fix an integer underflow
CVE-2023-53635 8.2 HIGH netfilter: conntrack: fix wrong ct->timeout value
CVE-2022-50555 7.8 HIGH tipc: fix a null-ptr-deref in tipc_topsrv_accept
CVE-2023-53659 7.8 HIGH iavf: Fix out-of-bounds when setting channels on remove
CVE-2023-53619 7.8 HIGH netfilter: conntrack: Avoid nf_ct_helper_hash uses after free
CVE-2023-53660 7.8 HIGH bpf, cpumap: Handle skb as well when clean up ptr_ring
CVE-2023-53643 7.8 HIGH nvme-tcp: don't access released socket during error recovery
CVE-2023-53645 7.8 HIGH bpf: Make bpf_refcount_acquire fallible for non-owning refs
CVE-2023-53646 7.8 HIGH drm/i915/perf: add sentinel to xehp_oa_b_counters
CVE-2023-53669 7.8 HIGH tcp: fix skb_copy_ubufs() vs BIG TCP
CVE-2023-53626 7.8 HIGH ext4: fix possible double unlock when moving a directory
CVE-2023-53627 7.8 HIGH scsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list
CVE-2022-50528 7.8 HIGH drm/amdkfd: Fix memory leakage
CVE-2023-53683 7.8 HIGH fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
CVE-2022-50518 7.8 HIGH parisc: Fix locking in pdc_iodc_print() firmware call

Showing top 20 of 118 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-50544

No comments yet


Leave a comment