cbcvebase.
CVE-2022-49924
published 2025-05-01

CVE-2022-49924: In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: Fix potential memory leak in fdp_nci_send() fdp_nci_send() will call…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: Fix potential memory leak in fdp_nci_send() fdp_nci_send() will call fdp_nci_i2c_write that will not free skb in the function. As a result, when fdp_nci_i2c_write() finished, the skb will memleak. fdp_nci_send() should free skb after fdp_nci_i2c_write() finished.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.8-1 (bookworm)linux 6.0.8-1 (bookworm)
linuxlinux
linuxlinux>= a06347c04c13e380afce0c9816df51f00b83faf1 < e8c11ee2d07f7c4dfa2ac0ea8efc4f627e58ea57e8c11ee2d07f7c4dfa2ac0ea8efc4f627e58ea57
linuxlinux>= a06347c04c13e380afce0c9816df51f00b83faf1 < 44bc1868a4f542502ea2221fe5ad88ca66d1c6b644bc1868a4f542502ea2221fe5ad88ca66d1c6b6
linuxlinux>= a06347c04c13e380afce0c9816df51f00b83faf1 < 1a7a898f8f7b56c0eaa2baf67a0c96235a30bc291a7a898f8f7b56c0eaa2baf67a0c96235a30bc29
linuxlinux>= a06347c04c13e380afce0c9816df51f00b83faf1 < 8e4aae6b8ca76afb1fb64dcb24be44ba814e7f8a8e4aae6b8ca76afb1fb64dcb24be44ba814e7f8a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 4.4 < 5.10.1545.10.154
linuxlinux_kernel>= 5.11 < 5.15.785.15.78
linuxlinux_kernel>= 5.16 < 6.0.86.0.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.