LiveActive security incident?Get immediate response
CVE Record

CVE-2022-50750: drm/panel/panel-sitronix-st7701: Remove panel on DSI attach failure

In the Linux kernel, the following vulnerability has been resolved: drm/panel/panel-sitronix-st7701: Remove panel on DSI attach failure In case mipi_dsi_attach() fails, call drm_panel_remove() to avoid memory leak.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

CVE-2022-50750 is a Linux kernel issue in the Sitronix ST7701 display panel driver. If attaching the panel over MIPI DSI fails, the driver may not clean up correctly, causing a memory leak. The public record does not provide CVSS scoring, real-world exploitation evidence, or a broad enterprise impact claim.

Executive priority

Treat as a targeted maintenance issue, not an emergency, unless your organization ships or operates Linux devices using this display panel driver. Include it in normal kernel update cycles and vendor firmware tracking.

Technical view

The flaw is in drm/panel/panel-sitronix-st7701. On mipi_dsi_attach() failure, the driver failed to call drm_panel_remove(), leaving allocated panel state behind. Kernel stable commits add the missing cleanup. Exposure depends on kernel version and whether this specific DRM panel driver is present and used.

Likely exposure

Most likely exposure is embedded, mobile, IoT, or appliance Linux systems using the Sitronix ST7701 MIPI DSI panel driver. Standard servers and cloud workloads are unlikely to be affected unless they include and exercise this driver path.

Exploitation context

The sources describe a memory leak during a hardware driver attach failure. They do not describe remote exploitation, privilege escalation, public exploit code, or active exploitation. CISA KEV status in the provided bundle is false.

Researcher notes

Evidence is limited to the CVE record and Linux stable commits. No CVSS, CWE, exploitability analysis, or affected distribution advisories are included. The affected-version data appears kernel-specific and should be verified against actual vendor kernel trees.

Mitigation direction

  • Review Linux vendor kernel advisories for CVE-2022-50750.
  • Apply kernel updates containing the referenced stable commits.
  • Prioritize devices using Sitronix ST7701 MIPI DSI panels.
  • If unsupported, ask the device vendor for a fixed kernel build.

Validation and detection

  • Inventory Linux kernel versions on relevant embedded or display devices.
  • Check whether the Sitronix ST7701 DRM panel driver is enabled.
  • Confirm the running kernel includes the referenced cleanup commit.
  • Validate remediation through vendor release notes or kernel source provenance.
Prepared
Confidence
medium
Sources
8

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-50750 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
7Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux849b2e3ff9698226ab91e034d52cbb1da92a5b4c, 849b2e3ff9698226ab91e034d52cbb1da92a5b4c, 849b2e3ff9698226ab91e034d52cbb1da92a5b4c, 849b2e3ff9698226ab91e034d52cbb1da92a5b4c, 849b2e3ff9698226ab91e034d52cbb1da92a5b4c, 849b2e3ff9698226ab91e034d52cbb1da92a5b4cunaffected
LinuxLinux5.1, 0, 5.4.229, 5.10.163, 5.15.86, 6.0.16, 6.1.2, 6.2affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.