cbcvebase.
CVE-2022-49704
published 2025-02-26

CVE-2022-49704: In the Linux kernel, the following vulnerability has been resolved: 9p: fix fid refcount leak in v9fs_vfs_get_link we check for protocol version later than…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.8th percentile
In the Linux kernel, the following vulnerability has been resolved: 9p: fix fid refcount leak in v9fs_vfs_get_link we check for protocol version later than required, after a fid has been obtained. Just move the version check earlier.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 6636b6dcc3db2258cd0585b8078c1c225c4b6dde < f0126bcaee81dabc1926012126aa74caa03a4c6ef0126bcaee81dabc1926012126aa74caa03a4c6e
linuxlinux>= 6636b6dcc3db2258cd0585b8078c1c225c4b6dde < e7b6d622bd812013eb39c8f4cd65b7ee8ede1e02e7b6d622bd812013eb39c8f4cd65b7ee8ede1e02
linuxlinux>= 6636b6dcc3db2258cd0585b8078c1c225c4b6dde < e5690f263208c5abce7451370b7786eb25b405ebe5690f263208c5abce7451370b7786eb25b405eb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.11 < 5.15.515.15.51
linuxlinux_kernel>= 5.16 < 5.18.85.18.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.