cbcvebase.
CVE-2022-49508
published 2025-02-26

CVE-2022-49508: In the Linux kernel, the following vulnerability has been resolved: HID: elan: Fix potential double free in elan_input_configured 'input' is a managed resource…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.0th percentile
In the Linux kernel, the following vulnerability has been resolved:

HID: elan: Fix potential double free in elan_input_configured

'input' is a managed resource allocated with devm_input_allocate_device(),
so there is no need to call input_free_device() explicitly or
there will be a double free.

According to the doc of devm_input_allocate_device():
* Managed input devices do not need to be explicitly unregistered or
* freed as it will be done automatically when owner device unbinds from
* its driver (or binding fails).

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 9a6a4193d65b853020ef0e66cecdf9e64a863883 < c92ec22a991778a096342cf1a917ae36c5c86a90c92ec22a991778a096342cf1a917ae36c5c86a90
linuxlinux>= 9a6a4193d65b853020ef0e66cecdf9e64a863883 < f1d4f19a796551edc6679a681ea1756b8c578c08f1d4f19a796551edc6679a681ea1756b8c578c08
linuxlinux>= 9a6a4193d65b853020ef0e66cecdf9e64a863883 < 6d0726725c7c560495f5ff364862a2cefea542e36d0726725c7c560495f5ff364862a2cefea542e3
linuxlinux>= 9a6a4193d65b853020ef0e66cecdf9e64a863883 < 24f9dfdaece9bd75bb8dbfdba83eddeefdf7dc4724f9dfdaece9bd75bb8dbfdba83eddeefdf7dc47
linuxlinux>= 9a6a4193d65b853020ef0e66cecdf9e64a863883 < 5291451851feeb66fd4bf0826710f482f3b1ab385291451851feeb66fd4bf0826710f482f3b1ab38
linuxlinux>= 9a6a4193d65b853020ef0e66cecdf9e64a863883 < 8bb1716507ebf12d50bbf181764481de3b6bc7fd8bb1716507ebf12d50bbf181764481de3b6bc7fd
linuxlinux>= 9a6a4193d65b853020ef0e66cecdf9e64a863883 < 1af20714fedad238362571620be0bd690ded05b61af20714fedad238362571620be0bd690ded05b6
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 4.17 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3
linuxlinux_kernel>= 5.5 < 5.10.1215.10.121

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.