CVE-2022-49403

In the Linux kernel, the following vulnerability has been resolved: lib/string_helpers: fix not adding strarray to device's resource list Add allocated strarray to device's resource list. This is a must to automatically release strarray when the device disappears. Without this fix we have a memory leak in the few drivers which use devm_kasprintf_strarray().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

17 Apr 2025, 20:28

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/a152eb42fcecfe41239c3c6695342f3a128593e7 - () https://git.kernel.org/stable/c/a152eb42fcecfe41239c3c6695342f3a128593e7 - Patch
References () https://git.kernel.org/stable/c/bf29edab0c9ff3d2633b8306a67d04c357e2a385 - () https://git.kernel.org/stable/c/bf29edab0c9ff3d2633b8306a67d04c357e2a385 - Patch
References () https://git.kernel.org/stable/c/cd290a9839cee2f6641558877e707bd373c8f6f1 - () https://git.kernel.org/stable/c/cd290a9839cee2f6641558877e707bd373c8f6f1 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CWE CWE-401
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: lib/string_helpers: se ha corregido el problema de no añadir strarray a la lista de recursos del dispositivo. Se añade el strarray asignado a la lista de recursos del dispositivo. Esto es imprescindible para liberar automáticamente strarray cuando el dispositivo desaparece. Sin esta corrección, tenemos una pérdida de memoria en los pocos controladores que utilizan devm_kasprintf_strarray().
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

26 Feb 2025, 07:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:01

Updated : 2025-04-17 20:28


NVD link : CVE-2022-49403

Mitre link : CVE-2022-49403

CVE.ORG link : CVE-2022-49403


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime