cbcvebase.
CVE-2022-49263
published 2025-02-26

CVE-2022-49263: In the Linux kernel, the following vulnerability has been resolved: brcmfmac: pcie: Release firmwares in the brcmf_pcie_setup error path This avoids leaking…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.2th percentile
In the Linux kernel, the following vulnerability has been resolved: brcmfmac: pcie: Release firmwares in the brcmf_pcie_setup error path This avoids leaking memory if brcmf_chip_get_raminfo fails. Note that the CLM blob is released in the device remove path.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 82f93cf46d6007ffa003b2d4a2834563b6b84d21 < d0ab87f8dcdfe72dc1d763be3392c1fc51a1ace2d0ab87f8dcdfe72dc1d763be3392c1fc51a1ace2
linuxlinux>= 82f93cf46d6007ffa003b2d4a2834563b6b84d21 < f3820ddaf4f3ac80c7401ccc6a42e663c9317f31f3820ddaf4f3ac80c7401ccc6a42e663c9317f31
linuxlinux>= 82f93cf46d6007ffa003b2d4a2834563b6b84d21 < a88337a06966f2d733ad9a97714b874469133f14a88337a06966f2d733ad9a97714b874469133f14
linuxlinux>= 82f93cf46d6007ffa003b2d4a2834563b6b84d21 < 4e0b507597e1a86e9b4c056ab274c427223cf8ea4e0b507597e1a86e9b4c056ab274c427223cf8ea
linuxlinux>= 82f93cf46d6007ffa003b2d4a2834563b6b84d21 < 0347bdfdb1529994ac3a4cb425087c477a74eb2c0347bdfdb1529994ac3a4cb425087c477a74eb2c
linuxlinux>= 82f93cf46d6007ffa003b2d4a2834563b6b84d21 < 5e90f0f3ead014867dade7a22f93958119f5efab5e90f0f3ead014867dade7a22f93958119f5efab
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.4 < 5.4.1895.4.189
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.