cbcvebase.
CVE-2022-48775
published 2024-07-16

CVE-2022-48775: In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Fix memory leak in vmbus_add_channel_kobj kobject_init_and_add() takes…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.5th percentile
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Fix memory leak in vmbus_add_channel_kobj kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add(): If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix memory leak by calling kobject_put().

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.11-1 (bookworm)linux 5.16.11-1 (bookworm)
linuxlinux
linuxlinux>= c2e5df616e1ae6c2a074cb241ebb65a318ebaf7c < 417947891bd5ae327f15efed1a0da2b12ef24962417947891bd5ae327f15efed1a0da2b12ef24962
linuxlinux>= c2e5df616e1ae6c2a074cb241ebb65a318ebaf7c < fe595759c2a4a5bb41c438474f15947d8ae32f5cfe595759c2a4a5bb41c438474f15947d8ae32f5c
linuxlinux>= c2e5df616e1ae6c2a074cb241ebb65a318ebaf7c < 91d8866ca55232d21995a3d54fac96de33c9e20c91d8866ca55232d21995a3d54fac96de33c9e20c
linuxlinux>= c2e5df616e1ae6c2a074cb241ebb65a318ebaf7c < c377e2ba78d3fe9a1f0b4ec424e75f81da7e81e9c377e2ba78d3fe9a1f0b4ec424e75f81da7e81e9
linuxlinux>= c2e5df616e1ae6c2a074cb241ebb65a318ebaf7c < 92e25b637cd4e010f776c86e4810300e773eac5c92e25b637cd4e010f776c86e4810300e773eac5c
linuxlinux>= c2e5df616e1ae6c2a074cb241ebb65a318ebaf7c < 8bc69f86328e87a0ffa79438430cc82f3aa6a1948bc69f86328e87a0ffa79438430cc82f3aa6a194
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.11-15.16.11-1
linuxlinux_kernel>= 0 < 5.16.11-15.16.11-1
linuxlinux_kernel>= 0 < 5.16.11-15.16.11-1
linuxlinux_kernel>= 4.15 < 4.19.2314.19.231
linuxlinux_kernel>= 4.20 < 5.4.1815.4.181
linuxlinux_kernel>= 5.11 < 5.15.255.15.25
linuxlinux_kernel>= 5.16 < 5.16.115.16.11
linuxlinux_kernel>= 5.5 < 5.10.1025.10.102

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.