cbcvebase.
CVE-2022-48706
published 2024-05-21

CVE-2022-48706: In the Linux kernel, the following vulnerability has been resolved: vdpa: ifcvf: Do proper cleanup if IFCVF init fails ifcvf_mgmt_dev leaks memory if it is not…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.9th percentile
In the Linux kernel, the following vulnerability has been resolved: vdpa: ifcvf: Do proper cleanup if IFCVF init fails ifcvf_mgmt_dev leaks memory if it is not freed before returning. Call is made to correct return statement so memory does not leak. ifcvf_init_hw does not take care of this so it is needed to do it here.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.15-1 (bookworm)linux 6.1.15-1 (bookworm)
linuxlinux
linuxlinux>= 378b2e956820ff5c082d05f42828badcfbabb614 < 5d2cc32c1c10bd889125d2adc16a6bc3338dcd3e5d2cc32c1c10bd889125d2adc16a6bc3338dcd3e
linuxlinux>= 378b2e956820ff5c082d05f42828badcfbabb614 < 6b04456e248761cf68f562f2fd7c04e591fcac946b04456e248761cf68f562f2fd7c04e591fcac94
linuxlinux_kernel< 6.1.136.1.13
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.