cbcvebase.
CVE-2022-48768
published 2024-06-20

CVE-2022-48768: In the Linux kernel, the following vulnerability has been resolved: tracing/histogram: Fix a potential memory leak for kstrdup() kfree() is missing on an error…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.3th percentile
In the Linux kernel, the following vulnerability has been resolved: tracing/histogram: Fix a potential memory leak for kstrdup() kfree() is missing on an error path to free the memory allocated by kstrdup(): p = param = kstrdup(data->params[i], GFP_KERNEL); So it is better to free it via kfree(p).

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.7-1 (bookworm)linux 5.16.7-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 38b67e60b6b582e81f9db1b2e7176cbbfbd3e574 < 8a8878ebb596281f50fc0b9a6e1f23f0d7f154e88a8878ebb596281f50fc0b9a6e1f23f0d7f154e8
linuxlinux>= 5.4.19 < 5.4.1765.4.176
linuxlinux>= 5.5.6 < 5.65.6
linuxlinux>= d380dcde9a07ca5de4805dee11f58a98ec0ad6ff < d71b06aa995007eafd247626d0669b9364c42ad7d71b06aa995007eafd247626d0669b9364c42ad7
linuxlinux>= d380dcde9a07ca5de4805dee11f58a98ec0ad6ff < e33fa4a46ee22de88a700e2e3d033da8214a5175e33fa4a46ee22de88a700e2e3d033da8214a5175
linuxlinux>= d380dcde9a07ca5de4805dee11f58a98ec0ad6ff < df86e2fe808c3536a9dba353cc2bebdfea00d0cfdf86e2fe808c3536a9dba353cc2bebdfea00d0cf
linuxlinux>= d380dcde9a07ca5de4805dee11f58a98ec0ad6ff < e629e7b525a179e29d53463d992bdee759c950fbe629e7b525a179e29d53463d992bdee759c950fb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 5.11 < 5.15.195.15.19
linuxlinux_kernel>= 5.16 < 5.16.55.16.5
linuxlinux_kernel>= 5.4.19 < 5.4.1765.4.176
linuxlinux_kernel>= 5.6 < 5.10.965.10.96

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.