Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix memory leak in query_regdb_file() In the function query_regdb_file() the alpha2 parameter is duplicated using kmemdup() and subsequently freed in regdb_fw_cb(). However, request_firmware_nowait() can fail without calling regdb_fw_cb() and thus leak memory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.15, < 4.19.267 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/0ede1a988299e95d54bd89551fd635980572e920Patch
- https://git.kernel.org/stable/c/219446396786330937bcd382a7bc4ccd767383bcPatch
- https://git.kernel.org/stable/c/38c9fa2cc6bf4b6e1a74057aef8b5cffd23d3264Patch
- https://git.kernel.org/stable/c/57b962e627ec0ae53d4d16d7bd1033e27e67677aPatch
- https://git.kernel.org/stable/c/e1e12180321f416d83444f2cdc9259e0f5093d35Patch
- https://git.kernel.org/stable/c/e9b5a4566d5bc71cc901be50d1fa24da00613120Patch
FAQ
What is CVE-2022-49881?
CVE-2022-49881 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix memory leak in query_regdb_file() In the function query_regdb_file() the alpha2 parameter is duplicated using ...
How severe is CVE-2022-49881?
CVE-2022-49881 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49881?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.