cbcvebase.
CVE-2022-49627
published 2025-02-26

CVE-2022-49627: In the Linux kernel, the following vulnerability has been resolved: ima: Fix potential memory leak in ima_init_crypto() On failure to allocate the SHA1 tfm…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ima: Fix potential memory leak in ima_init_crypto() On failure to allocate the SHA1 tfm, IMA fails to initialize and exits without freeing the ima_algo_array. Add the missing kfree() for ima_algo_array to avoid the potential memory leak.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 6d94809af6b0830c4dfcad661535a5939bcb8a7d < c1d9702ceb4a091da6bee380627596d1fba09274c1d9702ceb4a091da6bee380627596d1fba09274
linuxlinux>= 6d94809af6b0830c4dfcad661535a5939bcb8a7d < 601ae26aa2802a4c10c94d7388a99eabdbefab2b601ae26aa2802a4c10c94d7388a99eabdbefab2b
linuxlinux>= 6d94809af6b0830c4dfcad661535a5939bcb8a7d < 830de9667b3ada0a75a3f098dfc7159709fe397b830de9667b3ada0a75a3f098dfc7159709fe397b
linuxlinux>= 6d94809af6b0830c4dfcad661535a5939bcb8a7d < 067d2521874135267e681c19d42761c601d503d6067d2521874135267e681c19d42761c601d503d6
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.8 < 5.10.1325.10.132

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.