In the Linux kernel, the following vulnerability has been resolved:
spi: Fix simplification of devm_spi_register_controller
This reverts commit 59ebbe40fb51 ("spi: simplify
devm_spi_register_controller").
If devm_add_action() fails in devm_add_action_or_reset(),
devm_spi_unregister() will be called, it decreases the
refcount of 'ctlr->dev' to 0, then it will cause uaf in
the drivers that calling spi_put_controller() in error path.
References
Configurations
Configuration 1 (hide)
|
History
19 Nov 2025, 12:50
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CWE | CWE-416 | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| First Time |
Linux
Linux linux Kernel |
|
| Summary |
|
|
| References | () https://git.kernel.org/stable/c/34bab623ebfc08398499e463396b81abb4abe01e - Patch | |
| References | () https://git.kernel.org/stable/c/3c6bd448442b6c3f6843ac70d57201a13478dd47 - Patch | |
| References | () https://git.kernel.org/stable/c/43cc5a0afe4184a7fafe1eba32b5a11bb69c9ce0 - Patch | |
| References | () https://git.kernel.org/stable/c/445fb9c19cf45bd9472fd9babaa31c5e6c7d2720 - Patch |
18 Jun 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-06-18 11:15
Updated : 2025-11-19 12:50
NVD link : CVE-2022-50190
Mitre link : CVE-2022-50190
CVE.ORG link : CVE-2022-50190
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
