#VU111688 Improper resource shutdown or release in Linux kernel - CVE-2022-50029
Published: June 20, 2025 / Updated: June 21, 2025
Vulnerability identifier: #VU111688
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-50029
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to properly release resources within the drivers/clk/qcom/gcc-ipq8074.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/17d58499dc9c7e059dab7d170e9bae1e7e9c561b
- https://git.kernel.org/stable/c/1bf7305e79aab095196131bdc87a97796e0e3fac
- https://git.kernel.org/stable/c/38cee0d2b65eed42a44052de1bfdc0177b6c3f05
- https://git.kernel.org/stable/c/4203b76abe539f3cac258d4cf1e16e2dd95ea60f
- https://git.kernel.org/stable/c/459411b9f0180e3f382d7abfa3028dd3285984c3
- https://git.kernel.org/stable/c/6b90ab952401bd6c1a321dcfc0e0df080f2bc905
- https://git.kernel.org/stable/c/d401611a93b332914cf91eb9bc0b63fa1bdc17e9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.211