CVE-2022-50431: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ALSA: aoa: i2sbus: fix possible memory leak in i2sbus_add_dev() dev_set_name() in soundbus_add_one() allocates memory for name, it need be freed when of_device_register() fails, call soundbus_dev_put() to give up the reference that hold in device_initialize(), so that it can be freed in kobject_cleanup() when the refcount hit to 0. And other resources are also freed in i2sbus_release_dev(), so it can return 0 directly.
Affected products
- Linux Linux Kernel: from 2.6.18, before 4.9.332 (fixed in 4.9.332); from 4.10, before 4.14.298 (fixed in 4.14.298); from 4.15, before 4.19.264 (fixed in 4.19.264); from 4.20, before 5.4.223 (fixed in 5.4.223); from 5.5, before 5.10.153 (fixed in 5.10.153); from 5.11, before 5.15.77 (fixed in 5.15.77); …
Published 2025-10-01. Last modified 2026-06-17.