cbcvebase.
CVE-2022-49657
published 2025-02-26

CVE-2022-49657: In the Linux kernel, the following vulnerability has been resolved: usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need…

PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.1th percentile
In the Linux kernel, the following vulnerability has been resolved: usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case. v2: add Fixes tag v3: fix uninitialized buf pointer

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 877bd862f32b815d54ab5fc10a4fd903d7bf3012 < 3eed421ca5c809da93456f69203d164d5220be3d3eed421ca5c809da93456f69203d164d5220be3d
linuxlinux>= 877bd862f32b815d54ab5fc10a4fd903d7bf3012 < 5269209f54dd8dfd15f9383f3a3a1fe8370764f85269209f54dd8dfd15f9383f3a3a1fe8370764f8
linuxlinux>= 877bd862f32b815d54ab5fc10a4fd903d7bf3012 < d5165e657987ff4ba0ace896d4376a3718a9fbc3d5165e657987ff4ba0ace896d4376a3718a9fbc3
linuxlinux>= 877bd862f32b815d54ab5fc10a4fd903d7bf3012 < 04894ab34faf40ab72a8a5ab5b404bb0606bbbff04894ab34faf40ab72a8a5ab5b404bb0606bbbff
linuxlinux>= 877bd862f32b815d54ab5fc10a4fd903d7bf3012 < 0085da9df3dced730027923a6b48f58e9016af910085da9df3dced730027923a6b48f58e9016af91
linuxlinux>= 877bd862f32b815d54ab5fc10a4fd903d7bf3012 < db89582ff330556188da856e01382ccbf3a5e706db89582ff330556188da856e01382ccbf3a5e706
linuxlinux>= 877bd862f32b815d54ab5fc10a4fd903d7bf3012 < e7b4f69946a38209b4a4f660bf0e4cbed94f9b4be7b4f69946a38209b4a4f660bf0e4cbed94f9b4b
linuxlinux>= 877bd862f32b815d54ab5fc10a4fd903d7bf3012 < b55a21b764c1e182014630fa5486d717484ac58fb55a21b764c1e182014630fa5486d717484ac58f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 3.8 < 4.9.3234.9.323
linuxlinux_kernel>= 4.10 < 4.14.2884.14.288
linuxlinux_kernel>= 4.15 < 4.19.2524.19.252
linuxlinux_kernel>= 4.20 < 5.4.2055.4.205
linuxlinux_kernel>= 5.11 < 5.15.545.15.54
linuxlinux_kernel>= 5.16 < 5.18.115.18.11
linuxlinux_kernel>= 5.5 < 5.10.1305.10.130

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.