CVE-2022-50400

In the Linux kernel, the following vulnerability has been resolved: staging: greybus: audio_helper: remove unused and wrong debugfs usage In the greybus audio_helper code, the debugfs file for the dapm has the potential to be removed and memory will be leaked. There is also the very real potential for this code to remove ALL debugfs entries from the system, and it seems like this is what will really happen if this code ever runs. This all is very wrong as the greybus audio driver did not create this debugfs file, the sound core did and controls the lifespan of it. So remove all of the debugfs logic from the audio_helper code as there's no way it could be correct. If this really is needed, it can come back with a fixup for the incorrect usage of the debugfs_lookup() call which is what caused this to be noticed at all.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

12 Dec 2025, 20:38

Type Values Removed Values Added
CWE CWE-401
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/4dab0d27a4211a27135a6899d6c737e6e0759a11 - () https://git.kernel.org/stable/c/4dab0d27a4211a27135a6899d6c737e6e0759a11 - Patch
References () https://git.kernel.org/stable/c/5699afbff1fa2972722e863906c0320d55dd4d58 - () https://git.kernel.org/stable/c/5699afbff1fa2972722e863906c0320d55dd4d58 - Patch
References () https://git.kernel.org/stable/c/d0febad83e29d85bb66e4f5cac0115b022403338 - () https://git.kernel.org/stable/c/d0febad83e29d85bb66e4f5cac0115b022403338 - Patch
References () https://git.kernel.org/stable/c/d517cdeb904ddc0cbebcc959d43596426cac40b0 - () https://git.kernel.org/stable/c/d517cdeb904ddc0cbebcc959d43596426cac40b0 - Patch
References () https://git.kernel.org/stable/c/d835fa49d9589a780ff0d001bb7e6323238a4afb - () https://git.kernel.org/stable/c/d835fa49d9589a780ff0d001bb7e6323238a4afb - Patch
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

18 Sep 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-18 14:15

Updated : 2025-12-12 20:38


NVD link : CVE-2022-50400

Mitre link : CVE-2022-50400

CVE.ORG link : CVE-2022-50400


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime