cbcvebase.
CVE-2022-49210
published 2025-02-26

CVE-2022-49210: In the Linux kernel, the following vulnerability has been resolved: MIPS: pgalloc: fix memory leak caused by pgd_free() pgd page is freed by generic…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: MIPS: pgalloc: fix memory leak caused by pgd_free() pgd page is freed by generic implementation pgd_free() since commit f9cb654cb550 ("asm-generic: pgalloc: provide generic pgd_free()"), however, there are scenarios that the system uses more than one page as the pgd table, in such cases the generic implementation pgd_free() won't be applicable anymore. For example, when PAGE_SIZE_4KB is enabled and MIPS_VA_BITS_48 is not enabled in a 64bit system, the macro "PGD_ORDER" will be set as "1", which will cause allocating two pages as the pgd table. Well, at the same time, the generic implementation pgd_free() just free one pgd page, which will result in the memory leak. The memory leak can be easily detected by executing shell command: "while true; do ls > /dev/null; grep MemFree /proc/meminfo; done"

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= f9cb654cb550b7b87e8608b14fc3eca432429ffe < fa3d44424579972cc7c4fac3d9cf227798ebdfa0fa3d44424579972cc7c4fac3d9cf227798ebdfa0
linuxlinux>= f9cb654cb550b7b87e8608b14fc3eca432429ffe < d29cda15cab086d82d692de016f7249545d4b6b4d29cda15cab086d82d692de016f7249545d4b6b4
linuxlinux>= f9cb654cb550b7b87e8608b14fc3eca432429ffe < 5a8501d34b261906e4c76ec9da679f2cb4d309ed5a8501d34b261906e4c76ec9da679f2cb4d309ed
linuxlinux>= f9cb654cb550b7b87e8608b14fc3eca432429ffe < 1bf0d78c8cc3cf615a6e7bf33ada70b73592f0a11bf0d78c8cc3cf615a6e7bf33ada70b73592f0a1
linuxlinux>= f9cb654cb550b7b87e8608b14fc3eca432429ffe < 2bc5bab9a763d520937e4f3fe8df51c6a1eceb972bc5bab9a763d520937e4f3fe8df51c6a1eceb97
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.9 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.