cbcvebase.
CVE-2022-49467
published 2025-02-26

CVE-2022-49467: In the Linux kernel, the following vulnerability has been resolved: drm: msm: fix possible memory leak in mdp5_crtc_cursor_set() drm_gem_object_lookup will…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.3th percentile
In the Linux kernel, the following vulnerability has been resolved: drm: msm: fix possible memory leak in mdp5_crtc_cursor_set() drm_gem_object_lookup will call drm_gem_object_get inside. So cursor_bo needs to be put when msm_gem_get_and_pin_iova fails.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= e172d10a9c4acc69bb07cbe9142ded2df791ff1f < f8cd192752a1f613b14eee77783c6f0aebb49691f8cd192752a1f613b14eee77783c6f0aebb49691
linuxlinux>= e172d10a9c4acc69bb07cbe9142ded2df791ff1f < 449374565f349d4233beec811d4286fdfe5de44b449374565f349d4233beec811d4286fdfe5de44b
linuxlinux>= e172d10a9c4acc69bb07cbe9142ded2df791ff1f < 656aa3c51fc662064f17179b38ec3ce43af53bca656aa3c51fc662064f17179b38ec3ce43af53bca
linuxlinux>= e172d10a9c4acc69bb07cbe9142ded2df791ff1f < 33546183c16c7b9650682dc610bedd732d9c691933546183c16c7b9650682dc610bedd732d9c6919
linuxlinux>= e172d10a9c4acc69bb07cbe9142ded2df791ff1f < d544880482a5558ec06393b1b3d5dc9275b7a32bd544880482a5558ec06393b1b3d5dc9275b7a32b
linuxlinux>= e172d10a9c4acc69bb07cbe9142ded2df791ff1f < d63ffe3fb3f8327ca21cf91b6a14a2961bc629b4d63ffe3fb3f8327ca21cf91b6a14a2961bc629b4
linuxlinux>= e172d10a9c4acc69bb07cbe9142ded2df791ff1f < 947a844bb3ebff0f4736d244d792ce129f6700d7947a844bb3ebff0f4736d244d792ce129f6700d7
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 4.0 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3
linuxlinux_kernel>= 5.5 < 5.10.1215.10.121

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.