cbcvebase.
CVE-2022-48863
published 2024-07-16

CVE-2022-48863: In the Linux kernel, the following vulnerability has been resolved: mISDN: Fix memory leak in dsp_pipeline_build() dsp_pipeline_build() allocates dup pointer…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mISDN: Fix memory leak in dsp_pipeline_build() dsp_pipeline_build() allocates dup pointer by kstrdup(cfg), but then it updates dup variable by strsep(&dup, "|"). As a result when it calls kfree(dup), the dup variable contains NULL. Found by Linux Driver Verification project (linuxtesting.org) with SVACE.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.18-1 (bookworm)linux 5.16.18-1 (bookworm)
linuxlinux
linuxlinux>= 960366cf8dbb3359afaca30cf7fdbf69a6d6dda7 < a3d5fcc6cf2ecbba5a269631092570aa285a24cba3d5fcc6cf2ecbba5a269631092570aa285a24cb
linuxlinux>= 960366cf8dbb3359afaca30cf7fdbf69a6d6dda7 < 7777b1f795af1bb43867375d8a776080111aae1b7777b1f795af1bb43867375d8a776080111aae1b
linuxlinux>= 960366cf8dbb3359afaca30cf7fdbf69a6d6dda7 < 640445d6fc059d4514ffea79eb4196299e0e2d0f640445d6fc059d4514ffea79eb4196299e0e2d0f
linuxlinux>= 960366cf8dbb3359afaca30cf7fdbf69a6d6dda7 < c6a502c2299941c8326d029cfc8a3bc8a4607ad5c6a502c2299941c8326d029cfc8a3bc8a4607ad5
linuxlinux_kernel>= 0 < 5.10.106-15.10.106-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.4.0-196.2165.4.0-196.216
linuxlinux_kernel>= 0 < 4.4.0-259.2934.4.0-259.293
linuxlinux_kernel>= 0 < 4.15.0-229.2414.15.0-229.241
linuxlinux_kernel>= 2.6.27 < 5.10.1065.10.106
linuxlinux_kernel>= 5.11 < 5.15.295.15.29
linuxlinux_kernel>= 5.16 < 5.16.155.16.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.