cbcvebase.
CVE-2022-48669
published 2024-05-01

CVE-2022-48669: In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Fix potential memleak in papr_get_attr() `buf` is allocated in…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.2th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Fix potential memleak in papr_get_attr() `buf` is allocated in papr_get_attr(), and krealloc() of `buf` could fail. We need to free the original `buf` in the case of failure.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 3c14b73454cf9f6e2146443fdfbdfb912c0efed3 < a3f22feb2220a945d1c3282e34199e8bcdc5afc4a3f22feb2220a945d1c3282e34199e8bcdc5afc4
linuxlinux>= 3c14b73454cf9f6e2146443fdfbdfb912c0efed3 < 1699fb915b9f61794d559b55114c09a390aaf2341699fb915b9f61794d559b55114c09a390aaf234
linuxlinux>= 3c14b73454cf9f6e2146443fdfbdfb912c0efed3 < 7f7d39fe3d80d6143404940b2413010cf65270297f7d39fe3d80d6143404940b2413010cf6527029
linuxlinux>= 3c14b73454cf9f6e2146443fdfbdfb912c0efed3 < d0647c3e81eff62b66d46fd4e475318cb8cb3610d0647c3e81eff62b66d46fd4e475318cb8cb3610
linuxlinux>= 3c14b73454cf9f6e2146443fdfbdfb912c0efed3 < cda9c0d556283e2d4adaa9960b2dc19b16156baecda9c0d556283e2d4adaa9960b2dc19b16156bae
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.18 < 6.1.836.1.83
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.