LiveActive security incident?Get immediate response
CVE Record

CVE-2022-50637: cpufreq: qcom-hw: Fix memory leak in qcom_cpufreq_hw_read_lut()

In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom-hw: Fix memory leak in qcom_cpufreq_hw_read_lut() If "cpu_dev" fails to get opp table in qcom_cpufreq_hw_read_lut(), the program will return, resulting in "table" resource is not released.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2022-50637 is a Linux kernel memory leak in the Qualcomm hardware CPU frequency driver. If a lookup for CPU operating-performance data fails, allocated memory may not be released. Public sources do not provide CVSS, confirmed business impact, or active exploitation evidence.

Executive priority

Handle through normal kernel maintenance unless a vendor advisory raises severity for your environment. Prioritize asset identification for Qualcomm Linux platforms and apply fixed kernels when available.

Technical view

The issue is in qcom_cpufreq_hw_read_lut(). When cpu_dev fails to get an OPP table, the function returns without releasing the table resource. The CVE record lists Linux kernel exposure and stable kernel commits that resolve the leak.

Likely exposure

Most relevant to Linux systems using the Qualcomm qcom-hw cpufreq driver. The CVE source lists Linux kernel versions and stable commits, but applicability depends on kernel build, hardware platform, and vendor distribution packaging.

Exploitation context

No CISA KEV listing is reported in the provided data, and the sources do not state active exploitation. The public description does not describe attacker prerequisites, reachability, or a practical exploitation path.

Researcher notes

The record is sparse: no CVSS, CWE, exploit status, or detailed trigger conditions are provided. Analysis should focus on patch presence, affected kernel lineage, and whether the Qualcomm cpufreq hardware driver path is present in the target environment.

Mitigation direction

  • Check your Linux distribution or device vendor advisory for CVE-2022-50637 applicability.
  • Update to a kernel package containing the referenced stable fixes.
  • Prioritize Qualcomm-based Linux devices if they use the qcom-hw cpufreq driver.
  • If updates are unavailable, follow vendor guidance for risk reduction.

Validation and detection

  • Inventory Linux kernel versions across Qualcomm-based systems.
  • Confirm whether the qcom-hw cpufreq driver is built or loaded.
  • Verify kernel source or package includes one of the referenced stable commits.
  • Track vendor advisories for backported fixes using different version numbers.
Prepared
Confidence
medium
Sources
7

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-50637 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
6Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux51c843cf77bb52db6df947c4fedcfc62ae3b7b30, 51c843cf77bb52db6df947c4fedcfc62ae3b7b30, 51c843cf77bb52db6df947c4fedcfc62ae3b7b30, 51c843cf77bb52db6df947c4fedcfc62ae3b7b30, 51c843cf77bb52db6df947c4fedcfc62ae3b7b30unaffected
LinuxLinux5.9, 0, 5.10.163, 5.15.86, 6.0.16, 6.1.2, 6.2affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.