cbcvebase.
CVE-2022-49648
published 2025-02-26

CVE-2022-49648: In the Linux kernel, the following vulnerability has been resolved: tracing/histograms: Fix memory leak problem This reverts commit…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: tracing/histograms: Fix memory leak problem This reverts commit 46bbe5c671e06f070428b9be142cc4ee5cedebac. As commit 46bbe5c671e0 ("tracing: fix double free") said, the "double free" problem reported by clang static analyzer is: > In parse_var_defs() if there is a problem allocating > var_defs.expr, the earlier var_defs.name is freed. > This free is duplicated by free_var_defs() which frees > the rest of the list. However, if there is a problem allocating N-th var_defs.expr: + in parse_var_defs(), the freed 'earlier var_defs.name' is actually the N-th var_defs.name; + then in free_var_defs(), the names from 0th to (N-1)-th are freed; IF ALLOCATING PROBLEM HAPPENED HERE!!! -+ \ | 0th 1th (N-1)-th N-th V +-------------+-------------+-----+-------------+----------- var_defs: | name | expr | name | expr | ... | name | expr | name | /// +-------------+-------------+-----+-------------+----------- These two frees don't act on same name, so there was no "double free" problem before. Conversely, after that commit, we get a "memory leak" problem because the above "N-th var_defs.name" is not freed. If enable CONFIG_DEBUG_KMEMLEAK and inject a fault at where the N-th var_defs.expr allocated, then execute on shell like: $ echo 'hist:key=call_site:val=$v1,$v2:v1=bytes_req,v2=bytes_alloc' > \ /sys/kernel/debug/tracing/events/kmem/kmalloc/trigger Then kmemleak reports: unreferenced object 0xffff8fb100ef3518 (size 8): comm "bash", pid 196, jiffies 4295681690 (age 28.538s) hex dump (first 8 bytes): 76 31 00 00 b1 8f ff ff v1...... backtrace: [] kstrdup+0x2d/0x60 [] event_hist_trigger_parse+0x206f/0x20e0 [] trigger_process_regex+0xc0/0x110 [] event_trigger_write+0x75/0xd0 [] vfs_write+0xbb/0x2a0 [] ksys_write+0x59/0xd0 [] do_syscall_64+0x3a/0x80 [] entry_SYSCALL_64_after_hwframe+0x46/0xb0

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 240dd5118a9e0454f280ffeae63f22bd14735733 < eb622d5580b9e2ff694f62da6410618bd73853cbeb622d5580b9e2ff694f62da6410618bd73853cb
linuxlinux>= 4.19.149 < 4.19.2534.19.253
linuxlinux>= 46bbe5c671e06f070428b9be142cc4ee5cedebac < 78a1400c42ee11197eb1f0f85ba51df9a4fdfff078a1400c42ee11197eb1f0f85ba51df9a4fdfff0
linuxlinux>= 46bbe5c671e06f070428b9be142cc4ee5cedebac < 22eeff55679d9e7c0f768c79bfbd83e2f8142d8922eeff55679d9e7c0f768c79bfbd83e2f8142d89
linuxlinux>= 46bbe5c671e06f070428b9be142cc4ee5cedebac < 4d453eb5e1eec89971aa5b3262857ee26cfdffd34d453eb5e1eec89971aa5b3262857ee26cfdffd3
linuxlinux>= 46bbe5c671e06f070428b9be142cc4ee5cedebac < 7edc3945bdce9c39198a10d6129377a5c53559c27edc3945bdce9c39198a10d6129377a5c53559c2
linuxlinux>= 5.4.69 < 5.4.2075.4.207
linuxlinux>= 5.8.13 < 5.95.9
linuxlinux>= e92c490f104993cea35e5f5d5108ac12df1850ac < ecc6dec12c33aa92c086cd702af9f544ddaf3c75ecc6dec12c33aa92c086cd702af9f544ddaf3c75
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.19.149 < 4.19.2534.19.253
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.4.69 < 5.4.2075.4.207
linuxlinux_kernel>= 5.8.13 < 5.10.1325.10.132

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.