-

CVE-2022-50529

In the Linux kernel, the following vulnerability has been resolved:

test_firmware: fix memory leak in test_firmware_init()

When misc_register() failed in test_firmware_init(), the memory pointed
by test_fw_config->name is not released. The memory leak information is
as follows:
unreferenced object 0xffff88810a34cb00 (size 32):
  comm "insmod", pid 7952, jiffies 4294948236 (age 49.060s)
  hex dump (first 32 bytes):
    74 65 73 74 2d 66 69 72 6d 77 61 72 65 2e 62 69  test-firmware.bi
    6e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  n...............
  backtrace:
    [<ffffffff81b21fcb>] __kmalloc_node_track_caller+0x4b/0xc0
    [<ffffffff81affb96>] kstrndup+0x46/0xc0
    [<ffffffffa0403a49>] __test_firmware_config_init+0x29/0x380 [test_firmware]
    [<ffffffffa040f068>] 0xffffffffa040f068
    [<ffffffff81002c41>] do_one_initcall+0x141/0x780
    [<ffffffff816a72c3>] do_init_module+0x1c3/0x630
    [<ffffffff816adb9e>] load_module+0x623e/0x76a0
    [<ffffffff816af471>] __do_sys_finit_module+0x181/0x240
    [<ffffffff89978f99>] do_syscall_64+0x39/0xb0
    [<ffffffff89a0008b>] entry_SYSCALL_64_after_hwframe+0x63/0xcd

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < ed5cbafaf7ce8b86f19998c00eb020c8d49b017f
Version c92316bf8e94830a0225f2e904cbdbd173768419
Status affected
Version < 04dd47a2e169f2d4489636afa07ff0469aab49ab
Version c92316bf8e94830a0225f2e904cbdbd173768419
Status affected
Version < 628de998a3abfffb3f9677d2fb39a1d5dcb32fdb
Version c92316bf8e94830a0225f2e904cbdbd173768419
Status affected
Version < 0b5a89e8bce1ea43687742b4de8e216189ff94ac
Version c92316bf8e94830a0225f2e904cbdbd173768419
Status affected
Version < 357379d504c0c8b0834e206ad8c49e4b3c98ed4d
Version c92316bf8e94830a0225f2e904cbdbd173768419
Status affected
Version < 8d8c1d6a430f0aadb80036e2b1bc0a05f9fad247
Version c92316bf8e94830a0225f2e904cbdbd173768419
Status affected
Version < 6dd5fbd243f19f087dc79481acb7d69fb57fea2c
Version c92316bf8e94830a0225f2e904cbdbd173768419
Status affected
Version < 7610615e8cdb3f6f5bbd9d8e7a5d8a63e3cabf2e
Version c92316bf8e94830a0225f2e904cbdbd173768419
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 4.14
Status affected
Version < 4.14
Version 0
Status unaffected
Version <= 4.14.*
Version 4.14.303
Status unaffected
Version <= 4.19.*
Version 4.19.270
Status unaffected
Version <= 5.4.*
Version 5.4.229
Status unaffected
Version <= 5.10.*
Version 5.10.163
Status unaffected
Version <= 5.15.*
Version 5.15.86
Status unaffected
Version <= 6.0.*
Version 6.0.16
Status unaffected
Version <= 6.1.*
Version 6.1.2
Status unaffected
Version <= *
Version 6.2
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string