PT-2025-26116 · Linux+3 · Linux Kernel+3

Published

2023-05-09

·

Updated

2025-11-19

·

CVE-2022-50190

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, related to the simplification of devm spi register controller. The issue arises when devm add action() fails in devm add action or reset(), leading to devm spi unregister() being called, which decreases the refcount of 'ctlr->dev' to 0. This causes a use-after-free (uaf) in drivers that call spi put controller() in the error path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-50190
RHSA-2023:2458
RHSA-2023_2458
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse