cbcvebase.
CVE-2022-49206
published 2025-02-26

CVE-2022-49206: In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix memory leak in error flow for subscribe event routine In case the second…

PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.3th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix memory leak in error flow for subscribe event routine In case the second xa_insert() fails, the obj_event is not released. Fix the error unwind flow to free that memory to avoid a memory leak.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 7597385371425febdaa8c6a1da3625d4ffff16f5 < 0174a89663a5ef83617da15bf24c0af2f62b6c7f0174a89663a5ef83617da15bf24c0af2f62b6c7f
linuxlinux>= 7597385371425febdaa8c6a1da3625d4ffff16f5 < c98d903ff9e79c210beddea4e6bc15ac38e25aa5c98d903ff9e79c210beddea4e6bc15ac38e25aa5
linuxlinux>= 7597385371425febdaa8c6a1da3625d4ffff16f5 < 8dd392e352d3269938fea32061a74655a613f9298dd392e352d3269938fea32061a74655a613f929
linuxlinux>= 7597385371425febdaa8c6a1da3625d4ffff16f5 < d66498507801fd9a20307a15a0814a0a016c3cded66498507801fd9a20307a15a0814a0a016c3cde
linuxlinux>= 7597385371425febdaa8c6a1da3625d4ffff16f5 < 414b4e8738484379f18d6c4e780787c80dbf8a2c414b4e8738484379f18d6c4e780787c80dbf8a2c
linuxlinux>= 7597385371425febdaa8c6a1da3625d4ffff16f5 < 087f9c3f2309ed183f7e4b85ae57121d8663224d087f9c3f2309ed183f7e4b85ae57121d8663224d
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.3 < 5.4.1895.4.189
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.