CVE-2022-49369

MEDIUM EPSS 14.6%
Published Feb 26, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Feb 26, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: amt: fix possible memory leak in amt_rcv() If an amt receives packets and it finds socket. If it can't find a socket, it should free a received skb. But it doesn't. So, a memory leak would possibly occur.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
14.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-401

Affected Products 2

VendorProductVersionRange
linuxlinux_kernel*≥5.16  –  <5.17.15
linuxlinux_kernel*≥5.18  –  <5.18.4

References 3

  • git.kernel.org https://git.kernel.org/stable/c/1a1a0e80e005cbdc2c250fc858e1d8570f4e4acb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4b8032d39b276c52db57ff834c300405b9da2691
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/60d9c020c69977e138727b3577bc6a0458325e9c
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/1a1a0e80e005cbdc2c250fc858e1d8570f4e4acb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4b8032d39b276c52db57ff834c300405b9da2691
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/60d9c020c69977e138727b3577bc6a0458325e9c
    Patch