PT-2025-49457 · Linux+2 · Linux Kernel+2
Published
2025-12-08
·
Updated
2026-04-20
·
CVE-2022-50616
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a use-after-free (UAF) issue between the regulator and multi-function device (mfd) subsystems. This occurs because the regulator core allocates init data resources to the parent device instead of the child device during device tree (DT) lookup. The issue arises when the parent device is released while the regulator core is still operating on the init data, leading to a UAF condition. The root cause is the passing of the parent device as a parameter during the DT lookup process. This can occur when using mfd core to create child devices for regulators.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux Kernel
Red Hat