cbcvebase.
CVE-2022-49370
published 2025-02-26

CVE-2022-49370: In the Linux kernel, the following vulnerability has been resolved: firmware: dmi-sysfs: Fix memory leak in dmi_sysfs_register_handle kobject_init_and_add()…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.4th percentile
In the Linux kernel, the following vulnerability has been resolved: firmware: dmi-sysfs: Fix memory leak in dmi_sysfs_register_handle kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix this issue by calling kobject_put().

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < a9bfb37d6ba7c376b0d53337a4c5f5ff324bd725a9bfb37d6ba7c376b0d53337a4c5f5ff324bd725
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < ed38d04342dfbe9e5aca745c8b5eb4188a74f0efed38d04342dfbe9e5aca745c8b5eb4188a74f0ef
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < c66cc3c62870a27ea8f060a7e4c1ad8d26dd3f0dc66cc3c62870a27ea8f060a7e4c1ad8d26dd3f0d
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < a724634b2a49f6ff0177a9e19a5a92fc1545e1b7a724634b2a49f6ff0177a9e19a5a92fc1545e1b7
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < 985706bd3bbeffc8737bc05965ca8d24837bc7db985706bd3bbeffc8737bc05965ca8d24837bc7db
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < fdffa4ad8f6bf1ece877edfb807f2b2c729d8578fdffa4ad8f6bf1ece877edfb807f2b2c729d8578
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < 3ba359ebe914ac3f8c6c832b28007c14c39d37663ba359ebe914ac3f8c6c832b28007c14c39d3766
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < ec752973aa721ee281d5441e497364637c626c7bec752973aa721ee281d5441e497364637c626c7b
linuxlinux>= 948af1f0bbc8526448e8cbe3f8d3bf211bdf5181 < 660ba678f9998aca6db74f2dd912fa5124f0fa31660ba678f9998aca6db74f2dd912fa5124f0fa31
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 2.6.39 < 4.9.3184.9.318
linuxlinux_kernel>= 4.10 < 4.14.2834.14.283
linuxlinux_kernel>= 4.15 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.475.15.47
linuxlinux_kernel>= 5.16 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4
linuxlinux_kernel>= 5.5 < 5.10.1225.10.122

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.