CVE-2022-49403

Summary

In the Linux kernel, the following vulnerability has been resolved:

lib/string_helpers: fix not adding strarray to device's resource list

Add allocated strarray to device's resource list. This is a must to automatically release strarray when the device disappears.

Without this fix we have a memory leak in the few drivers which use devm_kasprintf_strarray().

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxacdb89b6c87a2d7b5c48a82756e6f5c6f599f60a < a152eb42fcecfe41239c3c6695342f3a128593e7affected
LinuxLinuxacdb89b6c87a2d7b5c48a82756e6f5c6f599f60a < bf29edab0c9ff3d2633b8306a67d04c357e2a385affected
LinuxLinuxacdb89b6c87a2d7b5c48a82756e6f5c6f599f60a < cd290a9839cee2f6641558877e707bd373c8f6f1affected
LinuxLinux5.17affected
LinuxLinux0 < 5.17unaffected
LinuxLinux5.17.14 <= 5.17.*unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References