-

CVE-2022-50190

In the Linux kernel, the following vulnerability has been resolved:

spi: Fix simplification of devm_spi_register_controller

This reverts commit 59ebbe40fb51 ("spi: simplify
devm_spi_register_controller").

If devm_add_action() fails in devm_add_action_or_reset(),
devm_spi_unregister() will be called, it decreases the
refcount of 'ctlr->dev' to 0, then it will cause uaf in
the drivers that calling spi_put_controller() in error path.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 445fb9c19cf45bd9472fd9babaa31c5e6c7d2720
Version 59ebbe40fb51e307032ae7f63b2749fad2d4635a
Status affected
Version < 34bab623ebfc08398499e463396b81abb4abe01e
Version 59ebbe40fb51e307032ae7f63b2749fad2d4635a
Status affected
Version < 3c6bd448442b6c3f6843ac70d57201a13478dd47
Version 59ebbe40fb51e307032ae7f63b2749fad2d4635a
Status affected
Version < 43cc5a0afe4184a7fafe1eba32b5a11bb69c9ce0
Version 59ebbe40fb51e307032ae7f63b2749fad2d4635a
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.13
Status affected
Version < 5.13
Version 0
Status unaffected
Version <= 5.15.*
Version 5.15.61
Status unaffected
Version <= 5.18.*
Version 5.18.18
Status unaffected
Version <= 5.19.*
Version 5.19.2
Status unaffected
Version <= *
Version 6.0
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.056
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string