{"id":"DEBIAN-CVE-2022-50578","details":"In the Linux kernel, the following vulnerability has been resolved:  class: fix possible memory leak in __class_register()  If class_add_groups() returns error, the 'cp-\u003esubsys' need be unregister, and the 'cp' need be freed.  We can not call kset_unregister() here, because the 'cls' will be freed in callback function class_release() and it's also freed in caller's error path, it will cause double free.  So fix this by calling kobject_del() and kfree_const(name) to cleanup kobject. Besides, call kfree() to free the 'cp'.  Fault injection test can trigger this:  unreferenced object 0xffff888102fa8190 (size 8):   comm \"modprobe\", pid 502, jiffies 4294906074 (age 49.296s)   hex dump (first 8 bytes):     70 6b 74 63 64 76 64 00                          pktcdvd.   backtrace:     [\u003c00000000e7c7703d\u003e] __kmalloc_track_caller+0x1ae/0x320     [\u003c000000005e4d70bc\u003e] kstrdup+0x3a/0x70     [\u003c00000000c2e5e85a\u003e] kstrdup_const+0x68/0x80     [\u003c000000000049a8c7\u003e] kvasprintf_const+0x10b/0x190     [\u003c0000000029123163\u003e] kobject_set_name_vargs+0x56/0x150     [\u003c00000000747219c9\u003e] kobject_set_name+0xab/0xe0     [\u003c0000000005f1ea4e\u003e] __class_register+0x15c/0x49a  unreferenced object 0xffff888037274000 (size 1024):   comm \"modprobe\", pid 502, jiffies 4294906074 (age 49.296s)   hex dump (first 32 bytes):     00 40 27 37 80 88 ff ff 00 40 27 37 80 88 ff ff  .@'7.....@'7....     00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00  .....N..........   backtrace:     [\u003c00000000151f9600\u003e] kmem_cache_alloc_trace+0x17c/0x2f0     [\u003c00000000ecf3dd95\u003e] __class_register+0x86/0x49a","modified":"2026-09-01T16:05:35.709100674Z","published":"2025-10-22T14:15:42.803Z","upstream":["CVE-2022-50578"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50578"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50578.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50578.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50578.json"}}],"schema_version":"1.9.0"}