net: hns: fix possible memory leak in hnae_ae_register()
Published Sep 16, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
Inject fault while probing module, if device_register() fails, but the refcount of kobject is not decreased to 0, the name allocated in dev_set_name() is leaked. Fix this by calling put_device(), so that name can be freed in callback function kobject_cleanup().
unreferenced object 0xffff00c01aba2100 (size 128): comm "systemd-udevd", pid 1259, jiffies 4294903284 (age 294.152s) hex dump (first 32 bytes): 68 6e 61 65 30 00 00 00 18 21 ba 1a c0 00 ff ff hnae0....!...... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<0000000034783f26>] slab_post_alloc_hook+0xa0/0x3e0 [<00000000748188f2>] __kmem_cache_alloc_node+0x164/0x2b0 [<00000000ab0743e8>] __kmalloc_node_track_caller+0x6c/0x390 [<000000006c0ffb13>] kvasprintf+0x8c/0x118 [<00000000fa27bfe1>] kvasprintf_const+0x60/0xc8 [<0000000083e10ed7>] kobject_set_name_vargs+0x3c/0xc0 [<000000000b87affc>] dev_set_name+0x7c/0xa0 [<000000003fd8fe26>] hnae_ae_register+0xcc/0x190 [hnae] [<00000000fe97edc9>] hns_dsaf_ae_init+0x9c/0x108 [hns_dsaf] [<00000000c36ff1eb>] hns_dsaf_probe+0x548/0x748 [hns_dsaf]
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.4
- Version 4.14.298StatusunaffectedConstraints<=4.14.*
- Version 4.19.264StatusunaffectedConstraints<=4.19.*
- Version 4.9.332StatusunaffectedConstraints<=4.9.*
- Version 5.10.152StatusunaffectedConstraints<=5.10.*
- Version 5.15.76StatusunaffectedConstraints<=5.15.*
- Version 5.4.221StatusunaffectedConstraints<=5.4.*
- Version 6.0.6StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.4 · < 4.9.332
- ≥ 4.10 · < 4.14.298
- ≥ 4.15 · < 4.19.264
- ≥ 4.20 · < 5.4.221
- ≥ 5.5 · < 5.10.152
- ≥ 5.11 · < 5.15.76
- ≥ 5.16 · < 6.0.6
- 6.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A memory leak in the HNS framework occurred when device_register() failed in hnae_ae_register(): the device name allocated by dev_set_name() wasn’t freed because put_device() wasn’t called on the error path. This is a low-risk, local issue affecting driver probe failure paths and requiring administrative privileges.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-50352 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2395847 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55610 Advisory
- https://git.kernel.org/stable/c/02dc0db19d944b4a90941db505ecf1aaec714be4 Patch
- https://git.kernel.org/stable/c/2974f3b330ef25f5d34a4948d04290c2cd7802cf Patch
- https://git.kernel.org/stable/c/3b78453cca046d3b03853f0d077ad3ad130db886 Patch
- https://git.kernel.org/stable/c/7ae1345f6ad715acbcdc9e1ac28153684fd498bb Patch
- https://git.kernel.org/stable/c/91f8f5342bee726ed5692583d58f69e7cc9ae60e Patch
- https://git.kernel.org/stable/c/a3c148955c22fe1d94d7a2096005679c1f22eddf Patch
- https://git.kernel.org/stable/c/dfc0337c6dceb6449403b33ecb141f4a1458a1e9 Patch
- https://git.kernel.org/stable/c/ff2f5ec5d009844ec28f171123f9e58750cef4bf Patch
- https://lore.kernel.org/linux-cve-announce/2025091641-CVE-2022-50352-8531@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50352
- https://www.cve.org/CVERecord?id=CVE-2022-50352
Change history (0)
No recorded changes yet.