cbcvebase.
CVE-2022-49331
published 2025-02-26

CVE-2022-49331: In the Linux kernel, the following vulnerability has been resolved: nfc: st21nfca: fix memory leaks in EVT_TRANSACTION handling Error paths do not free…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.6th percentile
In the Linux kernel, the following vulnerability has been resolved: nfc: st21nfca: fix memory leaks in EVT_TRANSACTION handling Error paths do not free previously allocated memory. Add devm_kfree() to those failure paths.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < 593773088d615a46a42c97e01a0550d192bb7f74593773088d615a46a42c97e01a0550d192bb7f74
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < d221ce54ce331c1a23be71eebf57f6a088632383d221ce54ce331c1a23be71eebf57f6a088632383
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < 6fce324b530dd74750ad870699e33eeed1029ded6fce324b530dd74750ad870699e33eeed1029ded
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < 3eca2c42daa4659965db6817479027cbc6df78993eca2c42daa4659965db6817479027cbc6df7899
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < 54423649bc0ed464b75807a7cf2857a5871f738f54423649bc0ed464b75807a7cf2857a5871f738f
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < f444ecd3f57f4ba5090fe8b6756933e37de4226ef444ecd3f57f4ba5090fe8b6756933e37de4226e
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < db836b97464d44340b568e041fd24602858713f7db836b97464d44340b568e041fd24602858713f7
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < 55904086041ba4ee4070187b36590f8f8d6df4cd55904086041ba4ee4070187b36590f8f8d6df4cd
linuxlinux>= 26fc6c7f02cb26c39c4733de3dbc3c0646fc1074 < 996419e0594abb311fb958553809f24f38e7abbe996419e0594abb311fb958553809f24f38e7abbe
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 4.0 < 4.9.3184.9.318
linuxlinux_kernel>= 4.10 < 4.14.2834.14.283
linuxlinux_kernel>= 4.15 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.475.15.47
linuxlinux_kernel>= 5.16 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4
linuxlinux_kernel>= 5.5 < 5.10.1225.10.122

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.