5.5
CVE-2022-49627
- EPSS 0.26%
- Veröffentlicht 26.02.2025 07:01:38
- Zuletzt bearbeitet 01.10.2025 21:15:41
- Erkennungen
ima: Fix potential memory leak in ima_init_crypto()
In the Linux kernel, the following vulnerability has been resolved: ima: Fix potential memory leak in ima_init_crypto() On failure to allocate the SHA1 tfm, IMA fails to initialize and exits without freeing the ima_algo_array. Add the missing kfree() for ima_algo_array to avoid the potential memory leak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.8 < 5.10.132
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.56
Linux ≫ Linux Kernel Version >= 5.16 < 5.18.13
Linux ≫ Linux Kernel Version 5.19 Update rc1
Linux ≫ Linux Kernel Version 5.19 Update rc2
Linux ≫ Linux Kernel Version 5.19 Update rc3
Linux ≫ Linux Kernel Version 5.19 Update rc4
Linux ≫ Linux Kernel Version 5.19 Update rc5
Linux ≫ Linux Kernel Version 5.19 Update rc6
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.18 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| CISA-ADP | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
https://git.kernel.org/stable/c/067d2521874135267e681c19d42761c601d503d6
https://git.kernel.org/stable/c/601ae26aa2802a4c10c94d7388a99eabdbefab2b
https://git.kernel.org/stable/c/830de9667b3ada0a75a3f098dfc7159709fe397b
https://git.kernel.org/stable/c/c1d9702ceb4a091da6bee380627596d1fba09274