Review reviewHigh

CVE-2022-50745

Linux

In the Linux kernel, the following vulnerability has been resolved: staging: media: tegra-video: fix device_node use after free At probe time this code path is followed: * tegra_csi_init * tegra_csi_channels_alloc * for_each_child_of_node(node, channel) -- iterates over channels * automatically gets 'channel' * tegra_csi_channel_alloc() * saves into chan->of_node a pointer to the channel OF node * automatically gets and puts 'channel' * now the node saved in chan->of_node has refcount 0, can disappear * tegra_csi_channels_init * iterates over channels * tegra_csi_channel_init -- uses chan->...

CVSS
7.8
EPSS
0.17%
6.12% percentile
CISA KEV
Not listed
Published
2025.12.24
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.17%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: staging: media: tegra-video: fix device_node use after free At probe time this code path is followed: * tegra_csi_init * tegra_csi_channels_alloc * for_each_child_of_node(node, channel) -- iterates over channels * automatically gets 'channel' * tegra_csi_channel_alloc() * saves into chan->of_node a pointer to the channel OF node * automatically gets and puts 'channel' * now the node saved in chan->of_node has refcount 0, can disappear * tegra_csi_channels_init * iterates over channels * tegra_csi_channel_init -- uses chan->...

Affected product and versions

Product
Linux
Affected versions
>= 1ebaeb09830f36c1111b72a95420814225bd761c < 5451efb2ca30f3c42b9efb8327ce35b62870dbd3, >= 1ebaeb09830f36c1111b72a95420814225bd761c < ce50c612458091d926ccb05d7db11d9f93532db2, >= 1ebaeb09830f36c1111b72a95420814225bd761c < 6512c9498fcb97e7c760e3ef86b2272f2c0f765f, >= 1ebaeb09830f36c1111b72a95420814225bd761c < 0fd003d3c708c80350a815eaf37b8e1114b976cf, >= 1ebaeb09830f36c1111b72a95420814225bd761c < c4d344163c3a7f90712525f931a6c016bbb35e18, >= 5.10
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2022-50745 — Linux | SECUFOCUS NOW