CVE-2022-27950Missing Release of Memory after Effective Lifetime in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 78.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateFeb 14

Description

In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-56cr-f967-877p: In drivers/hid/hid-elo2022-03-29
OSV
CVE-2022-27950: In drivers/hid/hid-elo2022-03-28

📋Vendor Advisories

5
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Red Hat
kernel: memory leak in drivers/hid/hid-elo.c2022-03-13
Microsoft
In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11 a memory leak exists for a certain hid_parse error condition.2022-03-08
Debian
CVE-2022-27950: linux - In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exist...2022
CISA
Apple Multiple Products Memory Initialization Vulnerability2021-11-03