PT-2025-40671 · Linux+3 · Linux Kernel+3

Published

2023-05-09

·

Updated

2025-12-04

·

CVE-2022-50484

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel's ALSA subsystem, specifically within the usb-audio driver. A memory leak can occur when the driver attempts to allocate resources, such as URBs (USB Request Blocks) or buffers, and encounters an allocation failure (-ENOMEM). If this failure happens during the allocation loop for synchronous endpoint URBs, partially allocated URBs may not be properly released, leading to a memory leak. The issue arises because the ep->nurbs variable is not set before the error handling path is executed, preventing the error handler from iterating over the complete list of URBs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
CESA-2023_2951
CVE-2022-50484
OESA-2025-2659
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
SUSE-SU-2025:4111-1
SUSE-SU-2025:4135-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4188-1
SUSE-SU-2025:4320-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse