CVE-2022-50669 addresses a name leak vulnerability within the Linux kernel's ocxl driver, specifically in the ocxl_file_register_afu() function. This issue arises when device_register() fails, leading to an unreleased device name. The fix involves properly calling put_device() to free the allocated name. The vulnerability has no assigned CVSS score, indicating a lack of formal severity assessment, and its FAUCET Risk Score is low at 7/100. Given it's a kernel-level memory leak, the attack vector would likely require local access, and its complexity is moderate, with potential impact being system instability or resource exhaustion rather than direct data compromise. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.2CNA affecteddefault affected | |
| Linux | Linux | >= 75ca758adbafc81804c39b2c200ecdc819a6c042, < 0cd05062371a49774e8a45258bdedf0bd6d3d327, >= 75ca758adbafc81804c39b2c200ecdc819a6c042, < 2fce8b3583d1641a1716486f408478b58e96ec91, >= 75ca758adbafc81804c39b2c200ecdc819a6c042, < 3299983a6bf628249ac650908e62d12de959341e, >= 75ca758adbafc81804c39b2c200ecdc819a6c042, < 557b7de055d1e230ddb6664c29d26917b8db9143, >= 75ca758adbafc81804c39b2c200ecdc819a6c042, < 7525741cb302a1672b8c3a5edb2a08e4229b5c7c, >= 75ca758adbafc81804c39b2c200ecdc819a6c042, < a4cb1004aeed2ab893a058fad00a5b41a12c4691CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.