cbcvebase.
CVE-2022-49807
published 2025-05-01

CVE-2022-49807: In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a memory leak in nvmet_auth_set_key When changing dhchap secrets we need to…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.5th percentile
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a memory leak in nvmet_auth_set_key When changing dhchap secrets we need to release the old secrets as well. kmemleak complaint: -- unreferenced object 0xffff8c7f44ed8180 (size 64): comm "check", pid 7304, jiffies 4295686133 (age 72034.246s) hex dump (first 32 bytes): 44 48 48 43 2d 31 3a 30 30 3a 4c 64 4c 4f 64 71 DHHC-1:00:LdLOdq 79 56 69 67 77 48 55 32 6d 5a 59 4c 7a 35 59 38 yVigwHU2mZYLz5Y8 backtrace: [] kstrdup+0x2e/0x60 [] 0xffffffffc0e07ee6 [] 0xffffffffc0dff783 [] configfs_write_iter+0xb1/0x120 [] vfs_write+0x2be/0x3c0 [] ksys_write+0x5f/0xe0 [] do_syscall_64+0x38/0x90 [] entry_SYSCALL_64_after_hwframe+0x63/0xcd

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.10-1 (bookworm)linux 6.0.10-1 (bookworm)
linuxlinux
linuxlinux>= db1312dd95488b5e6ff362ff66fcf953a46b1821 < 65710ea51d4a185592c7b14c9e33d0c4a364f07465710ea51d4a185592c7b14c9e33d0c4a364f074
linuxlinux>= db1312dd95488b5e6ff362ff66fcf953a46b1821 < 0a52566279b4ee65ecd2503d7b7342851f84755c0a52566279b4ee65ecd2503d7b7342851f84755c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 6.0 < 6.0.106.0.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.