cbcvebase.
CVE-2022-49959
published 2025-06-18

CVE-2022-49959: In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix memory leak at failed datapath creation…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.4th percentile
In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix memory leak at failed datapath creation ovs_dp_cmd_new()->ovs_dp_change()->ovs_dp_set_upcall_portids() allocates array via kmalloc. If for some reason new_vport() fails during ovs_dp_cmd_new() dp->upcall_portids must be freed. Add missing kfree. Kmemleak example: unreferenced object 0xffff88800c382500 (size 64): comm "dump_state", pid 323, jiffies 4294955418 (age 104.347s) hex dump (first 32 bytes): 5e c2 79 e4 1f 7a 38 c7 09 21 38 0c 80 88 ff ff ^.y..z8..!8..... 03 00 00 00 0a 00 00 00 14 00 00 00 28 00 00 00 ............(... backtrace: [] ovs_dp_set_upcall_portids+0x38/0xa0 [] ovs_dp_change+0x63/0xe0 [] ovs_dp_cmd_new+0x1f0/0x380 [] genl_family_rcv_msg_doit+0xea/0x150 [] genl_rcv_msg+0xdc/0x1e0 [] netlink_rcv_skb+0x50/0x100 [] genl_rcv+0x24/0x40 [] netlink_unicast+0x23e/0x360 [] netlink_sendmsg+0x24e/0x4b0 [] sock_sendmsg+0x62/0x70 [] ____sys_sendmsg+0x230/0x270 [] ___sys_sendmsg+0x88/0xd0 [] __sys_sendmsg+0x59/0xa0 [] do_syscall_64+0x3b/0x90 [] entry_SYSCALL_64_after_hwframe+0x63/0xcd

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= b83d23a2a38b1770da0491257ae81d52307f7816 < ca54b2bfaab385778e55a9fd33f6c31e7f743b48ca54b2bfaab385778e55a9fd33f6c31e7f743b48
linuxlinux>= b83d23a2a38b1770da0491257ae81d52307f7816 < c0c1c0241917459644326a1a3102207c871ae159c0c1c0241917459644326a1a3102207c871ae159
linuxlinux>= b83d23a2a38b1770da0491257ae81d52307f7816 < a87406f4adee9c53b311d8a1ba2849c69e29a6d0a87406f4adee9c53b311d8a1ba2849c69e29a6d0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 4.15.0-246.2584.15.0-246.258
linuxlinux_kernel>= 5.15 < 5.15.665.15.66
linuxlinux_kernel>= 5.16 < 5.19.85.19.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.