cbcvebase.
CVE-2022-49468
published 2025-02-26

CVE-2022-49468: In the Linux kernel, the following vulnerability has been resolved: thermal/core: Fix memory leak in __thermal_cooling_device_register() I got memory leak as…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
24.1th percentile
In the Linux kernel, the following vulnerability has been resolved: thermal/core: Fix memory leak in __thermal_cooling_device_register() I got memory leak as follows when doing fault injection test: unreferenced object 0xffff888010080000 (size 264312): comm "182", pid 102533, jiffies 4296434960 (age 10.100s) hex dump (first 32 bytes): 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N.......... ff ff ff ff ff ff ff ff 40 7f 1f b9 ff ff ff ff ........@....... backtrace: [] kmalloc_order_trace+0x1d/0x110 mm/slab_common.c:969 [] __kmalloc+0x373/0x420 include/linux/slab.h:510 [] thermal_cooling_device_setup_sysfs+0x15d/0x2d0 include/linux/slab.h:586 [] __thermal_cooling_device_register+0x332/0xa60 drivers/thermal/thermal_core.c:927 [] devm_thermal_of_cooling_device_register+0x6b/0xf0 drivers/thermal/thermal_core.c:1041 [] max6650_probe.cold+0x557/0x6aa drivers/hwmon/max6650.c:211 [] i2c_device_probe+0x472/0xac0 drivers/i2c/i2c-core-base.c:561 If device_register() fails, thermal_cooling_device_destroy_sysfs() need be called to free the memory allocated in thermal_cooling_device_setup_sysfs().

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 8ea229511e06f9635ecc338dcbe0db41a73623f0 < 18530bedd221160823f63ccc20dd55c7a03edbcf18530bedd221160823f63ccc20dd55c7a03edbcf
linuxlinux>= 8ea229511e06f9635ecc338dcbe0db41a73623f0 < 21ccc58b671aea924f2481cf5c1cf0ebbfd3552d21ccc58b671aea924f2481cf5c1cf0ebbfd3552d
linuxlinux>= 8ea229511e06f9635ecc338dcbe0db41a73623f0 < 3802171f0b5b8b831f4ade5c827547cb323a5bb23802171f0b5b8b831f4ade5c827547cb323a5bb2
linuxlinux>= 8ea229511e06f9635ecc338dcbe0db41a73623f0 < 9abdf0c0184230f0cb5c6685aabf33dda89aa9fb9abdf0c0184230f0cb5c6685aabf33dda89aa9fb
linuxlinux>= 8ea229511e06f9635ecc338dcbe0db41a73623f0 < 98a160e898c0f4a979af9de3ab48b4b1d42d1dbb98a160e898c0f4a979af9de3ab48b4b1d42d1dbb
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 4.14 < 5.10.1215.10.121
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.