cbcvebase.
CVE-2022-49713
published 2025-02-26

CVE-2022-49713: In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: Fix memory leak in dwc2_hcd_init usb_create_hcd will alloc memory for hcd, and…

PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.3th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: Fix memory leak in dwc2_hcd_init usb_create_hcd will alloc memory for hcd, and we should call usb_put_hcd to free it when platform_get_resource() fails to prevent memory leak. goto error2 label instead error1 to fix this.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2754fa3b73df7d0ae042f3ed6cfd9df9042f6262 < a44a8a762f7fe9ad3c065813d058e835a6180cb2a44a8a762f7fe9ad3c065813d058e835a6180cb2
linuxlinux>= 4.14.250 < 4.14.2854.14.285
linuxlinux>= 4.19.210 < 4.19.2494.19.249
linuxlinux>= 4b7f4a0eb92bf37bea4cd838c7f83ea42823ca8b < 981ee40649e5fd9550f82db1fbb3bfab037da346981ee40649e5fd9550f82db1fbb3bfab037da346
linuxlinux>= 5.10.72 < 5.10.1245.10.124
linuxlinux>= 5.14.11 < 5.155.15
linuxlinux>= 5.4.152 < 5.4.2005.4.200
linuxlinux>= 856e6e8e0f9300befa87dde09edb578555c99a82 < 701d8ec01e0f229d4db6f43d3d64ee479120cbeb701d8ec01e0f229d4db6f43d3d64ee479120cbeb
linuxlinux>= 856e6e8e0f9300befa87dde09edb578555c99a82 < 52bfcedbfd5bf962dbdcb6e761f4d0dd3ba26dfd52bfcedbfd5bf962dbdcb6e761f4d0dd3ba26dfd
linuxlinux>= 856e6e8e0f9300befa87dde09edb578555c99a82 < 3755278f078460b021cd0384562977bf2039a57a3755278f078460b021cd0384562977bf2039a57a
linuxlinux>= 8b9c1c33e51d0959f2aec573dfbac0ffd3f5c0b7 < 6506aff2dc2f7059aa3d45ee2e8639b25e87090f6506aff2dc2f7059aa3d45ee2e8639b25e87090f
linuxlinux>= a7182993dd8e09f96839ddc3ac54f9b37370d282 < 84e6d0af87e27bbc0db94f2e7323b34abe17b6e584e6d0af87e27bbc0db94f2e7323b34abe17b6e5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.14.250 < 4.14.2854.14.285
linuxlinux_kernel>= 4.19.210 < 4.19.2494.19.249
linuxlinux_kernel>= 5.10.72 < 5.10.1245.10.124
linuxlinux_kernel>= 5.14.11 < 5.15.495.15.49
linuxlinux_kernel>= 5.16 < 5.18.65.18.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.