cbcvebase.
CVE-2022-49821
published 2025-05-01

CVE-2022-49821: In the Linux kernel, the following vulnerability has been resolved: mISDN: fix possible memory leak in mISDN_dsp_element_register() Afer commit 1fa5ae857bb1…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: mISDN: fix possible memory leak in mISDN_dsp_element_register() Afer commit 1fa5ae857bb1 ("driver core: get rid of struct device's bus_id string array"), the name of device is allocated dynamically, use put_device() to give up the reference, so that the name can be freed in kobject_cleanup() when the refcount is 0. The 'entry' is going to be freed in mISDN_dsp_dev_release(), so the kfree() is removed. list_del() is called in mISDN_dsp_dev_release(), so it need be initialized.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.10-1 (bookworm)linux 6.0.10-1 (bookworm)
linuxlinux
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < bbd53d05c4c892080ef3b617eff4f57903acecb9bbd53d05c4c892080ef3b617eff4f57903acecb9
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < b119bedbefb7dd9ed8bf8cb9f1056504250d610eb119bedbefb7dd9ed8bf8cb9f1056504250d610e
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 727ed7d28348c026c7ef4d852f3d0e5054d376e8727ed7d28348c026c7ef4d852f3d0e5054d376e8
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 0f2c681900a01e3f23789bca26d88268c3d5b51d0f2c681900a01e3f23789bca26d88268c3d5b51d
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 083a2c9ef82e184bdf0b9f9a1e5fc38d32afbb47083a2c9ef82e184bdf0b9f9a1e5fc38d32afbb47
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 7a05e3929668c8cfef495c69752a9e91fac4878f7a05e3929668c8cfef495c69752a9e91fac4878f
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < d4b8394725079670be309f9a35ad88a8cbbaaefdd4b8394725079670be309f9a35ad88a8cbbaaefd
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 98a2ac1ca8fd6eca6867726fe238d06e75eb1acd98a2ac1ca8fd6eca6867726fe238d06e75eb1acd
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 2.6.30 < 4.9.3344.9.334
linuxlinux_kernel>= 4.10 < 4.14.3004.14.300
linuxlinux_kernel>= 4.15 < 4.19.2674.19.267
linuxlinux_kernel>= 4.20 < 5.4.2255.4.225
linuxlinux_kernel>= 5.11 < 5.15.805.15.80
linuxlinux_kernel>= 5.16 < 6.0.106.0.10
linuxlinux_kernel>= 5.5 < 5.10.1565.10.156

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.