IT

Tracker / CVE-2022-49370

CVE-2022-49370

Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: firmware: dmi-sysfs: Fix memory leak in dmi_sysfs_register_handle kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix this issue by calling kobject_put().

Affected products and versions

linux linux_kernel · 2.6.39 → 4.9.318
linux linux_kernel · 4.10 → 4.14.283
linux linux_kernel · 4.15 → 4.19.247
linux linux_kernel · 4.20 → 5.4.198
linux linux_kernel · 5.11 → 5.15.47
linux linux_kernel · 5.16 → 5.17.15
linux linux_kernel · 5.18 → 5.18.4
linux linux_kernel · 5.5 → 5.10.122

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References