CVE-2022-49027
published 2024-10-21CVE-2022-49027: In the Linux kernel, the following vulnerability has been resolved: iavf: Fix error handling in iavf_init_module() The iavf_init_module() won't destroy…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.25%
16.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
iavf: Fix error handling in iavf_init_module()
The iavf_init_module() won't destroy workqueue when pci_register_driver()
failed. Call destroy_workqueue() when pci_register_driver() failed to
prevent the resource leak.
Similar to the handling of u132_hcd_init in commit f276e002793c
("usb: u132-hcd: fix resource leak")
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.12-1 (bookworm) | linux 6.0.12-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 2803b16c10ea7eec170c485388f5f26ae30e92fe < 971c55f0763b480e63ceb7a22beb19be2509e5ed | 971c55f0763b480e63ceb7a22beb19be2509e5ed |
| linux | linux | >= 2803b16c10ea7eec170c485388f5f26ae30e92fe < 0d9f5bd54b913018031c5b964fc1f9a31f5f6cb5 | 0d9f5bd54b913018031c5b964fc1f9a31f5f6cb5 |
| linux | linux | >= 2803b16c10ea7eec170c485388f5f26ae30e92fe < bd477b891a4fa084561234eed4afacb3001dd359 | bd477b891a4fa084561234eed4afacb3001dd359 |
| linux | linux | >= 2803b16c10ea7eec170c485388f5f26ae30e92fe < 227d8d2f7f2278b8468c5531b0cd0f2a905b4486 | 227d8d2f7f2278b8468c5531b0cd0f2a905b4486 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.12-1 | 6.0.12-1 |
| linux | linux_kernel | >= 0 < 6.0.12-1 | 6.0.12-1 |
| linux | linux_kernel | >= 0 < 6.0.12-1 | 6.0.12-1 |
| linux | linux_kernel | >= 4.6 < 5.10.158 | 5.10.158 |
| linux | linux_kernel | >= 5.11 < 5.15.82 | 5.15.82 |
| linux | linux_kernel | >= 5.16 < 6.0.12 | 6.0.12 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: iavf: Fix error handling in iavf_init_module()
vendor_redhat·2024-10-21·CVSS 5.5
CVE-2022-49027 [MEDIUM] CWE-772 kernel: iavf: Fix error handling in iavf_init_module()
kernel: iavf: Fix error handling in iavf_init_module()
In the Linux kernel, the following vulnerability has been resolved:
iavf: Fix error handling in iavf_init_module()
The iavf_init_module() won't destroy workqueue when pci_register_driver()
failed. Call destroy_workqueue() when pci_register_driver() failed to
prevent the resource leak.
Similar to the handling of u132_hcd_init in commit f276e002793c
("usb: u132-hcd: fix resource leak")
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel (Red Hat Ente
Debian
CVE-2022-49027: linux - In the Linux kernel, the following vulnerability has been resolved: iavf: Fix e...
vendor_debian·2022·CVSS 5.5
CVE-2022-49027 [MEDIUM] CVE-2022-49027: linux - In the Linux kernel, the following vulnerability has been resolved: iavf: Fix e...
In the Linux kernel, the following vulnerability has been resolved: iavf: Fix error handling in iavf_init_module() The iavf_init_module() won't destroy workqueue when pci_register_driver() failed. Call destroy_workqueue() when pci_register_driver() failed to prevent the resource leak. Similar to the handling of u132_hcd_init in commit f276e002793c ("usb: u132-hcd: fix resource leak")
Scope: local
bookworm: resolved (fixed in 6.0.12-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.12-1)
sid: resolved (fixed in 6.0.12-1)
trixie: resolved (fixed in 6.0.12-1)
GHSA
GHSA-4h4p-36mp-83pj: In the Linux kernel, the following vulnerability has been resolved:
iavf: Fix error handling in iavf_init_module()
The iavf_init_module() won't dest
ghsa_unreviewed·2024-10-21
CVE-2022-49027 [MEDIUM] GHSA-4h4p-36mp-83pj: In the Linux kernel, the following vulnerability has been resolved:
iavf: Fix error handling in iavf_init_module()
The iavf_init_module() won't dest
In the Linux kernel, the following vulnerability has been resolved:
iavf: Fix error handling in iavf_init_module()
The iavf_init_module() won't destroy workqueue when pci_register_driver()
failed. Call destroy_workqueue() when pci_register_driver() failed to
prevent the resource leak.
Similar to the handling of u132_hcd_init in commit f276e002793c
("usb: u132-hcd: fix resource leak")
OSV
CVE-2022-49027: In the Linux kernel, the following vulnerability has been resolved: iavf: Fix error handling in iavf_init_module() The iavf_init_module() won't destro
osv·2024-10-21·CVSS 5.5
CVE-2022-49027 [MEDIUM] CVE-2022-49027: In the Linux kernel, the following vulnerability has been resolved: iavf: Fix error handling in iavf_init_module() The iavf_init_module() won't destro
In the Linux kernel, the following vulnerability has been resolved: iavf: Fix error handling in iavf_init_module() The iavf_init_module() won't destroy workqueue when pci_register_driver() failed. Call destroy_workqueue() when pci_register_driver() failed to prevent the resource leak. Similar to the handling of u132_hcd_init in commit f276e002793c ("usb: u132-hcd: fix resource leak")
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-21
Published