LiveActive security incident?Get immediate response
CVE Record

CVE-2022-50664: media: dvb-frontends: fix leak of memory fw

In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: fix leak of memory fw

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

CVE-2022-50664 is a Linux kernel issue in DVB frontend media drivers where firmware memory was leaked. The public record does not provide a CVSS score, exploit evidence, or detailed impact. Business urgency is mainly for Linux systems using or shipping DVB/media hardware support, especially appliances or endpoints with media capture/tuner functionality.

Executive priority

Handle through normal kernel maintenance unless your environment relies on DVB/media devices. There is no cited active exploitation or severity score, but kernel memory leaks can affect availability on exposed systems.

Technical view

The CVE record states the Linux kernel fixed a firmware memory leak in media/dvb-frontends. Affected kernel ranges are listed across long-term branches, with multiple stable commit references. The available sources do not describe attacker prerequisites, trigger conditions, crash behavior, privilege requirements, or whether the leak is exploitable beyond resource exhaustion.

Likely exposure

Exposure is most plausible on Linux systems with DVB frontend drivers present, enabled, or packaged for supported media/tuner hardware. General-purpose servers without DVB/media hardware are less likely to be practically exposed, but kernel package backports should still be checked.

Exploitation context

No active exploitation is indicated; the source bundle marks KEV as false. Public sources provided do not include proof-of-concept activity or weaponized exploitation. The likely risk is availability degradation from memory leakage if the vulnerable code path can be repeatedly reached.

Researcher notes

The record is sparse: no CVSS, CWE, exploitability details, or trigger path are provided. Analysis should focus on the referenced stable commits, affected kernel branches, and whether downstream vendors backported the firmware memory release fix into supported kernels.

Mitigation direction

  • Update Linux kernels using vendor or distribution security guidance.
  • Confirm whether referenced stable kernel fixes are included or backported.
  • Prioritize systems with DVB/media hardware or loaded DVB frontend modules.
  • If no vendor advisory exists, monitor kernel stable and distribution notices.

Validation and detection

  • Inventory running kernel versions across Linux assets.
  • Check whether DVB frontend drivers or related media modules are present.
  • Review distribution changelogs for CVE-2022-50664 or the referenced commits.
  • Confirm patched kernels are deployed and active after reboot.
Prepared
Confidence
medium
Sources
11

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-50664 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
10Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux55f51efdb696ff6e9d2056377d05268a97f3d4e4, 55f51efdb696ff6e9d2056377d05268a97f3d4e4, 55f51efdb696ff6e9d2056377d05268a97f3d4e4, 55f51efdb696ff6e9d2056377d05268a97f3d4e4, 55f51efdb696ff6e9d2056377d05268a97f3d4e4, 55f51efdb696ff6e9d2056377d05268a97f3d4e4, 55f51efdb696ff6e9d2056377d05268a97f3d4e4, 55f51efdb696ff6e9d2056377d05268a97f3d4e4, 55f51efdb696ff6e9d2056377d05268a97f3d4e4unaffected
LinuxLinux2.6.13, 0, 4.9.337, 4.14.303, 4.19.270, 5.4.229, 5.10.163, 5.15.86, 6.0.16, 6.1.2, 6.2affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.