CVE-2022-50484: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential memory leaks When the driver hits -ENOMEM at allocating a URB or a buffer, it aborts and goes to the error path that releases the all previously allocated resources. However, when -ENOMEM hits at the middle of the sync EP URB allocation loop, the partially allocated URBs might be left without released, because ep->nurbs is still zero at that point. Fix it by setting ep->nurbs at first, so that the error handler loops over the full URB list.
Affected products
- Linux Linux Kernel: from 3.5, before 4.9.331 (fixed in 4.9.331); from 4.10, before 4.14.296 (fixed in 4.14.296); from 4.15, before 4.19.262 (fixed in 4.19.262); from 4.20, before 5.4.220 (fixed in 5.4.220); from 5.5, before 5.10.150 (fixed in 5.10.150); from 5.11, before 5.15.75 (fixed in 5.15.75); …
Published 2025-10-04. Last modified 2026-06-17.