CVE-2022-50499: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: media: dvb-core: Fix double free in dvb_register_device() In function dvb_register_device() -> dvb_register_media_device() -> dvb_create_media_entity(), dvb->entity is allocated and initialized. If the initialization fails, it frees the dvb->entity, and return an error code. The caller takes the error code and handles the error by calling dvb_media_device_free(), which unregisters the entity and frees the field again if it is not NULL. As dvb->entity may not NULLed in dvb_create_media_entity() when the allocation of dvbdev->pad fails, a double free may occur. This may also cause an Use After free in media_device_unregister_entity(). Fix this by storing NULL to dvb->entity when it is freed.

Affected products

  • Linux Linux Kernel: from 4.9.195, before 4.9.337 (fixed in 4.9.337); from 4.14.147, before 4.14.303 (fixed in 4.14.303); from 4.19.77, before 4.19.270 (fixed in 4.19.270); from 5.2.19, before 5.3 (fixed in 5.3); from 5.3.4, before 5.4.229 (fixed in 5.4.229); from 5.5, before 5.10.163 (fixed in 5.10.163); …

Published 2025-10-04. Last modified 2026-06-17.