CVE-2022-50578 Details
Description
In the Linux kernel, the following vulnerability has been resolved: class: fix possible memory leak in __class_register() If class_add_groups() returns error, the 'cp->subsys' need be unregister, and the 'cp' need be freed. We can not call kset_unregister() here, because the 'cls' will be freed in callback function class_release() and it's also freed in caller's error path, it will cause double free. So fix this by calling kobject_del() and kfree_const(name) to cleanup kobject. Besides, call kfree() to free the 'cp'. Fault injection test can trigger this: unreferenced object 0xffff888102fa8190 (size 8): comm "modprobe", pid 502, jiffies 4294906074 (age 49.296s) hex dump (first 8 bytes): 70 6b 74 63 64 76 64 00 pktcdvd. backtrace: [<00000000e7c7703d>] __kmalloc_track_caller+0x1ae/0x320 [<000000005e4d70bc>] kstrdup+0x3a/0x70 [<00000000c2e5e85a>] kstrdup_const+0x68/0x80 [<000000000049a8c7>] kvasprintf_const+0x10b/0x190 [<0000000029123163>] kobject_set_name_vargs+0x56/0x150 [<00000000747219c9>] kobject_set_name+0xab/0xe0 [<0000000005f1ea4e>] __class_register+0x15c/0x49a unreferenced object 0xffff888037274000 (size 1024): comm "modprobe", pid 502, jiffies 4294906074 (age 49.296s) hex dump (first 32 bytes): 00 40 27 37 80 88 ff ff 00 40 27 37 80 88 ff ff .@'7.....@'7.... 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N.......... backtrace: [<00000000151f9600>] kmem_cache_alloc_trace+0x17c/0x2f0 [<00000000ecf3dd95>] __class_register+0x86/0x49a
A memory leak vulnerability has been identified in the Linux kernel's class registration process. This issue arises in the '__class_register()' function, where the 'cp' structure is not properly freed if 'class_add_groups()' returns an error. The 'cp->subsys' needs to be unregistered, and the 'cp' must be freed to prevent a memory leak. However, calling 'kset_unregister()' is problematic because the 'cls' will be freed in the 'class_release()' callback and also in the caller's error path, leading to a double free situation. This vulnerability can be triggered by a fault injection test that simulates an error in group addition, leaving unreferenced objects in memory.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version where this issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/18a7200646958cf8e1b8a933de08122fc50676cd | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/3bb9c92c27624ad076419a70f2b1a30cd1f8bbbd | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/3e0efc3f3f5e5c73996782f8db69963e501bb878 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/417ef049e3fd3b0d2593c1d5ffa3d0d5d0a018a7 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/4efa5443817c1b6de22d401aeca5b2481e835f8c | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/8c3e8a6bdb5253b97ad532570f8b5db5f7a06407 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/abaedb68a769e6bf36836b55a2f49b531c5f3f7b | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/e764ad5918a099ebeb909ccff83893a714e497e1 | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Oct 22, 2025 | New CVE Received | kernel.org |
Volerion