CVE-2022-48753

In the Linux kernel, the following vulnerability has been resolved: block: fix memory leak in disk_register_independent_access_ranges kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix this issue by adding kobject_put(). Callback function blk_ia_ranges_sysfs_release() in kobject_put() can handle the pointer "iars" properly.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

18 Sep 2024, 16:03

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/fe4214a07e0b53d2af711f57519e33739c5df23f - () https://git.kernel.org/stable/c/fe4214a07e0b53d2af711f57519e33739c5df23f - Patch
References () https://git.kernel.org/stable/c/83114df32ae779df57e0af99a8ba6c3968b2ba3d - () https://git.kernel.org/stable/c/83114df32ae779df57e0af99a8ba6c3968b2ba3d - Patch
CWE CWE-401
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

20 Jun 2024, 12:43

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-20 12:15

Updated : 2024-10-30 16:35


NVD link : CVE-2022-48753

Mitre link : CVE-2022-48753


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime