cbcvebase.
CVE-2022-49190
published 2025-02-26

CVE-2022-49190: In the Linux kernel, the following vulnerability has been resolved: kernel/resource: fix kfree() of bootmem memory again Since commit ebff7d8f270d ("mem…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved: kernel/resource: fix kfree() of bootmem memory again Since commit ebff7d8f270d ("mem hotunplug: fix kfree() of bootmem memory"), we could get a resource allocated during boot via alloc_resource(). And it's required to release the resource using free_resource(). Howerver, many people use kfree directly which will result in kernel BUG. In order to fix this without fixing every call site, just leak a couple of bytes in such corner case.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= ebff7d8f270d045338d9f4796014f4db429a17f9 < 3379a60f6bb4afcd9c456e340ac525ae649d3ce73379a60f6bb4afcd9c456e340ac525ae649d3ce7
linuxlinux>= ebff7d8f270d045338d9f4796014f4db429a17f9 < a9e88c2618d228d7a4e7e515cf30dc0d0d813f27a9e88c2618d228d7a4e7e515cf30dc0d0d813f27
linuxlinux>= ebff7d8f270d045338d9f4796014f4db429a17f9 < d7faa04a44a0c37ac3d222fa8e0bdcbfcee9c0c8d7faa04a44a0c37ac3d222fa8e0bdcbfcee9c0c8
linuxlinux>= ebff7d8f270d045338d9f4796014f4db429a17f9 < ab86020070999e758ce2e60c4348f20bf7ddba56ab86020070999e758ce2e60c4348f20bf7ddba56
linuxlinux>= ebff7d8f270d045338d9f4796014f4db429a17f9 < 0cbcc92917c5de80f15c24d033566539ad6968920cbcc92917c5de80f15c24d033566539ad696892
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 3.10 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.