cbcvebase.
CVE-2022-49729
published 2025-02-26

CVE-2022-49729: In the Linux kernel, the following vulnerability has been resolved: nfc: nfcmrvl: Fix memory leak in nfcmrvl_play_deferred Similar to the handling of…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.8th percentile
In the Linux kernel, the following vulnerability has been resolved: nfc: nfcmrvl: Fix memory leak in nfcmrvl_play_deferred Similar to the handling of play_deferred in commit 19cfe912c37b ("Bluetooth: btusb: Fix memory leak in play_deferred"), we thought a patch might be needed here as well. Currently usb_submit_urb is called directly to submit deferred tx urbs after unanchor them. So the usb_giveback_urb_bh would failed to unref it in usb_unanchor_urb and cause memory leak. Put those urbs in tx_anchor to avoid the leak, and also fix the error handling.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= f26e30cc6b50ba81e30ca3016c29ad4b48b93eaa < 1eb0afecfb9cd0f38424b82bd9aaa542310934ee1eb0afecfb9cd0f38424b82bd9aaa542310934ee
linuxlinux>= f26e30cc6b50ba81e30ca3016c29ad4b48b93eaa < f21f908347712b8288ffe83b531b5e977042b29cf21f908347712b8288ffe83b531b5e977042b29c
linuxlinux>= f26e30cc6b50ba81e30ca3016c29ad4b48b93eaa < 3e7c7df6991ac349f2fa8540047757df666e610f3e7c7df6991ac349f2fa8540047757df666e610f
linuxlinux>= f26e30cc6b50ba81e30ca3016c29ad4b48b93eaa < 6b4d8b44e7163a77fe942f5b80e1651c1b78c5376b4d8b44e7163a77fe942f5b80e1651c1b78c537
linuxlinux>= f26e30cc6b50ba81e30ca3016c29ad4b48b93eaa < 0eeec1a8b0cd38c47edeb042980a6aeacecf35ed0eeec1a8b0cd38c47edeb042980a6aeacecf35ed
linuxlinux>= f26e30cc6b50ba81e30ca3016c29ad4b48b93eaa < 6616872cfe7f0474a22dd1f12699f95bcf81a54d6616872cfe7f0474a22dd1f12699f95bcf81a54d
linuxlinux>= f26e30cc6b50ba81e30ca3016c29ad4b48b93eaa < 3eadc560c1919b8193d17334145dad9a917960e43eadc560c1919b8193d17334145dad9a917960e4
linuxlinux>= f26e30cc6b50ba81e30ca3016c29ad4b48b93eaa < 8a4d480702b71184fabcf379b80bf7539716752e8a4d480702b71184fabcf379b80bf7539716752e
linuxlinux_kernel< 4.9.3204.9.320
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.10 < 4.14.2854.14.285
linuxlinux_kernel>= 4.15 < 4.19.2494.19.249
linuxlinux_kernel>= 4.20 < 5.4.2005.4.200
linuxlinux_kernel>= 5.11 < 5.15.495.15.49
linuxlinux_kernel>= 5.16 < 5.18.65.18.6
linuxlinux_kernel>= 5.5 < 5.10.1245.10.124

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.