PT-2025-41025 · Linux+4 · Linux Kernel+4

Published

2022-11-22

·

Updated

2025-12-04

·

CVE-2022-50520

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A resource leak exists in the radeon atrm get bios() function within the DRM/Radeon driver. Specifically, a PCI device reference count leak can occur if the loop within the function is broken with a valid pdev pointer. The missing call to pci dev put() results in the reference count not being decremented, leading to a leak.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-12801
CESA-2023_7077
CVE-2022-50520
OESA-2025-2659
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
SUSE-SU-2025:4111-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4320-1

Affected Products

Centos
Linux Kernel
Radeon
Red Hat
Suse