cbcvebase.
CVE-2022-49801
published 2025-05-01

CVE-2022-49801: In the Linux kernel, the following vulnerability has been resolved: tracing: Fix memory leak in tracing_read_pipe() kmemleak reports this issue: unreferenced…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix memory leak in tracing_read_pipe() kmemleak reports this issue: unreferenced object 0xffff888105a18900 (size 128): comm "test_progs", pid 18933, jiffies 4336275356 (age 22801.766s) hex dump (first 32 bytes): 25 73 00 90 81 88 ff ff 26 05 00 00 42 01 58 04 %s......&...B.X. 03 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __kmalloc_node_track_caller+0x4a/0x140 [] krealloc+0x8d/0xf0 [] trace_iter_expand_format+0x99/0x150 [] trace_check_vprintf+0x1e0/0x11d0 [] trace_event_printf+0xb6/0xf0 [] trace_raw_output_bpf_trace_printk+0x89/0xc0 [] print_trace_line+0x73c/0x1480 [] tracing_read_pipe+0x45c/0x9f0 [] vfs_read+0x17b/0x7c0 [] ksys_read+0xed/0x1c0 [] do_syscall_64+0x3b/0x90 [] entry_SYSCALL_64_after_hwframe+0x63/0xcd iter->fmt alloced in tracing_read_pipe() -> .. ->trace_iter_expand_format(), but not freed, to fix, add free in tracing_release_pipe()

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.10-1 (bookworm)linux 6.0.10-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.10.190 < 5.115.11
linuxlinux>= efbbdaa22bb78761bff8dfdde027ad04bedd47ce < 2c21ee020ce43d744ecd7f3e9bddfcaafef270ce2c21ee020ce43d744ecd7f3e9bddfcaafef270ce
linuxlinux>= efbbdaa22bb78761bff8dfdde027ad04bedd47ce < a7d3f8f33c113478737bc61bb32ec5f9a987da7da7d3f8f33c113478737bc61bb32ec5f9a987da7d
linuxlinux>= efbbdaa22bb78761bff8dfdde027ad04bedd47ce < 649e72070cbbb8600eb823833e4748f5a0815116649e72070cbbb8600eb823833e4748f5a0815116
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 5.10.190 < 5.115.11
linuxlinux_kernel>= 5.12 < 5.15.805.15.80
linuxlinux_kernel>= 5.16 < 6.0.106.0.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.