CVE-2022-50404: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: fbdev: fbcon: release buffer when fbcon_do_set_font() failed syzbot is reporting memory leak at fbcon_do_set_font() [1], for commit a5a923038d70 ("fbdev: fbcon: Properly revert changes when vc_resize() failed") missed that the buffer might be newly allocated by fbcon_set_font().

Affected products

  • Linux Linux Kernel: from 5.15.64, before 5.15.86 (fixed in 5.15.86); from 5.19.6, before 6.0 (fixed in 6.0); from 6.0.1, before 6.0.16 (fixed in 6.0.16); from 6.1, before 6.1.2 (fixed in 6.1.2); version 6.0 only

Published 2025-09-18. Last modified 2026-06-17.