CVE-2022-50641
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50641 is a reference count (refcount) leak vulnerability in the Linux kernel's HSI (High-Speed Synchronous Serial Interface) subsystem, specifically in the omap_ssi driver's ssi_probe function. The flaw arises because the code fails to call of_node_put() on a child device tree node when returning or breaking early from a for_each_available_child_of_node() loop, resulting in a kernel resource leak. It affects Linux kernel versions from 3.16 up to (but not including) the patched stable releases. The vulnerability was published on December 9, 2025, and carries an estimated CVSS severity of Medium with an EPSS score of approximately 0.033% (Feedly, CIRCL).

Technical details

The root cause is improper resource management (CWE-772: Missing Release of Resource after Effective Lifetime) in the ssi_probe() function of drivers/hsi/controllers/omap_ssi.c. When the for_each_available_child_of_node() macro iterates over device tree child nodes and an early return or break occurs, the reference count on the current child of_node is not decremented via of_node_put(), causing a kernel reference count leak. This is a local, kernel-space issue requiring the affected hardware (OMAP SSI controller) to be present or the driver to be loaded; it is not remotely exploitable. The fix was backported to multiple stable kernel branches (Feedly, CIRCL).

Impact

The primary impact is a kernel memory resource leak — specifically, device tree node reference counts are not properly released, which can lead to memory not being freed over time. On systems with the OMAP SSI hardware or where the omap_ssi driver is loaded, repeated probe failures could gradually exhaust kernel memory resources, potentially contributing to system instability or denial of service in long-running environments. There is no known path to privilege escalation, code execution, or data exfiltration from this vulnerability (Feedly).

Exploitability

There is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2022-50641. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033%, reflecting a very low probability of exploitation in the wild. Detection coverage exists via Nessus plugin 278324 and Qualys detection ID 760731 (Feedly, Tenable).

Mitigation and workarounds

The fix has been backported to multiple Linux stable kernel branches. Patched versions include: 4.9.331, 4.14.296, 4.19.262, 5.4.220, 5.10.150, 5.15.75, 5.19.17, 6.0.3, and 6.1 (mainline). Users should update to the appropriate patched stable kernel release for their distribution. SUSE Linux has also issued kernel security updates addressing this CVE (Feedly, Linux Security SUSE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74726NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-modules
NoYesAug 22, 2026
CVE-2026-74719NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-partner
NoYesAug 22, 2026
CVE-2026-74717NONEN/A
  • Linux Kernel logoLinux Kernel
  • rtla
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management