CVE-2022-49370

MEDIUM EPSS 19.6%
Published Feb 26, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Feb 26, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: firmware: dmi-sysfs: Fix memory leak in dmi_sysfs_register_handle kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix this issue by calling kobject_put().

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
19.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-401

Affected Products 8

VendorProductVersionRange
linuxlinux_kernel*≥2.6.39  –  <4.9.318
linuxlinux_kernel*≥4.10  –  <4.14.283
linuxlinux_kernel*≥4.15  –  <4.19.247
linuxlinux_kernel*≥4.20  –  <5.4.198
linuxlinux_kernel*≥5.5  –  <5.10.122
linuxlinux_kernel*≥5.11  –  <5.15.47
linuxlinux_kernel*≥5.16  –  <5.17.15
linuxlinux_kernel*≥5.18  –  <5.18.4

References 9

  • git.kernel.org https://git.kernel.org/stable/c/3ba359ebe914ac3f8c6c832b28007c14c39d3766
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/660ba678f9998aca6db74f2dd912fa5124f0fa31
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/985706bd3bbeffc8737bc05965ca8d24837bc7db
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a724634b2a49f6ff0177a9e19a5a92fc1545e1b7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a9bfb37d6ba7c376b0d53337a4c5f5ff324bd725
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c66cc3c62870a27ea8f060a7e4c1ad8d26dd3f0d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ec752973aa721ee281d5441e497364637c626c7b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ed38d04342dfbe9e5aca745c8b5eb4188a74f0ef
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fdffa4ad8f6bf1ece877edfb807f2b2c729d8578
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/3ba359ebe914ac3f8c6c832b28007c14c39d3766
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/660ba678f9998aca6db74f2dd912fa5124f0fa31
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/985706bd3bbeffc8737bc05965ca8d24837bc7db
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a724634b2a49f6ff0177a9e19a5a92fc1545e1b7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a9bfb37d6ba7c376b0d53337a4c5f5ff324bd725
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c66cc3c62870a27ea8f060a7e4c1ad8d26dd3f0d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ec752973aa721ee281d5441e497364637c626c7b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ed38d04342dfbe9e5aca745c8b5eb4188a74f0ef
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fdffa4ad8f6bf1ece877edfb807f2b2c729d8578
    Patch