CVE-2022-50170
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/06/2025
Last modified:
28/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
kunit: executor: Fix a memory leak on failure in kunit_filter_tests<br />
<br />
It&#39;s possible that memory allocation for &#39;filtered&#39; will fail, but for the<br />
copy of the suite to succeed. In this case, the copy could be leaked.<br />
<br />
Properly free &#39;copy&#39; in the error case for the allocation of &#39;filtered&#39;<br />
failing.<br />
<br />
Note that there may also have been a similar issue in<br />
kunit_filter_subsuites, before it was removed in "kunit: flatten<br />
kunit_suite*** to kunit_suite** in .kunit_test_suites".<br />
<br />
This was reported by clang-analyzer via the kernel test robot, here:<br />
https://lore.kernel.org/all/c8073b8e-7b9e-0830-4177-87c12f16349c@intel.com/<br />
<br />
And by smatch via Dan Carpenter and the kernel test robot:<br />
https://lore.kernel.org/all/202207101328.ASjx88yj-lkp@intel.com/
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.17.14 (including) | 5.18 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.18.3 (including) | 5.18.18 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.19 (including) | 5.19.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



