{"id":"DEBIAN-CVE-2022-50545","details":"In the Linux kernel, the following vulnerability has been resolved:  r6040: Fix kmemleak in probe and remove  There is a memory leaks reported by kmemleak:    unreferenced object 0xffff888116111000 (size 2048):     comm \"modprobe\", pid 817, jiffies 4294759745 (age 76.502s)     hex dump (first 32 bytes):       00 c4 0a 04 81 88 ff ff 08 10 11 16 81 88 ff ff  ................       08 10 11 16 81 88 ff ff 00 00 00 00 00 00 00 00  ................     backtrace:       [\u003cffffffff815bcd82\u003e] kmalloc_trace+0x22/0x60       [\u003cffffffff827e20ee\u003e] phy_device_create+0x4e/0x90       [\u003cffffffff827e6072\u003e] get_phy_device+0xd2/0x220       [\u003cffffffff827e7844\u003e] mdiobus_scan+0xa4/0x2e0       [\u003cffffffff827e8be2\u003e] __mdiobus_register+0x482/0x8b0       [\u003cffffffffa01f5d24\u003e] r6040_init_one+0x714/0xd2c [r6040]       ...  The problem occurs in probe process as follows:   r6040_init_one:     mdiobus_register       mdiobus_scan    \u003c- alloc and register phy_device,                          the reference count of phy_device is 3     r6040_mii_probe       phy_connect     \u003c- connect to the first phy_device,                          so the reference count of the first                          phy_device is 4, others are 3     register_netdev   \u003c- fault inject succeeded, goto error handling path      // error handling path     err_out_mdio_unregister:       mdiobus_unregister(lp-\u003emii_bus);     err_out_mdio:       mdiobus_free(lp-\u003emii_bus);    \u003c- the reference count of the first                                        phy_device is 1, it is not released                                        and other phy_devices are released   // similarly, the remove process also has the same problem  The root cause is traced to the phy_device is not disconnected when removes one r6040 device in r6040_remove_one() or on error handling path after r6040_mii probed successfully. In r6040_mii_probe(), a net ethernet device is connected to the first PHY device of mii_bus, in order to notify the connected driver when the link status changes, which is the default behavior of the PHY infrastructure to handle everything. Therefore the phy_device should be disconnected when removes one r6040 device or on error handling path.  Fix it by adding phy_disconnect() when removes one r6040 device or on error handling path after r6040_mii probed successfully.","modified":"2026-09-01T16:05:35.659218170Z","published":"2025-10-07T16:15:38.943Z","upstream":["CVE-2022-50545"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50545"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50545.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50545.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50545.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}