PT-2025-49457 · Linux+2 · Linux Kernel+2

Published

2025-12-08

·

Updated

2026-04-20

·

CVE-2022-50616

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a use-after-free (UAF) issue between the regulator and multi-function device (mfd) subsystems. This occurs because the regulator core allocates init data resources to the parent device instead of the child device during device tree (DT) lookup. The issue arises when the parent device is released while the regulator core is still operating on the init data, leading to a UAF condition. The root cause is the passing of the parent device as a parameter during the DT lookup process. This can occur when using mfd core to create child devices for regulators.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2022-50616
OESA-2026-1341
RHSA-2023:6583

Affected Products

Debian
Linux Kernel
Red Hat