CVE-2022-50642
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2025
Last modified:
09/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
platform/chrome: cros_ec_typec: zero out stale pointers<br />
<br />
`cros_typec_get_switch_handles` allocates four pointers when obtaining<br />
type-c switch handles. These pointers are all freed if failing to obtain<br />
any of them; therefore, pointers in `port` become stale. The stale<br />
pointers eventually cause use-after-free or double free in later code<br />
paths. Zeroing out all pointer fields after freeing to eliminate these<br />
stale pointers.



