CVE-2022-49566
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: qat - fix memory leak in RSA
When an RSA key represented in form 2 (as defined in PKCS #1 V2.1) is used, some components of the private key persist even after the TFM is released. Replace the explicit calls to free the buffers in qat_rsa_exit_tfm() with a call to qat_rsa_clear_ctx() which frees all buffers referenced in the TFM context.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 879f77e9071f029e1c9bd5a75814ecf51370f846 < a843925e0287eebb4aa808666bf22c664dfe4c53 | affected |
| Linux | Linux | 879f77e9071f029e1c9bd5a75814ecf51370f846 < 0f967fdc09955221a1951a279481b0bf4d359941 | affected |
| Linux | Linux | 879f77e9071f029e1c9bd5a75814ecf51370f846 < 80a52e1ee7757b742f96bfb0d58f0c14eb6583d0 | affected |
| Linux | Linux | 4.8 | affected |
| Linux | Linux | 0 < 4.8 | unaffected |
| Linux | Linux | 5.15.58 <= 5.15.* | unaffected |
| Linux | Linux | 5.18.15 <= 5.18.* | unaffected |
| Linux | Linux | 5.19 <= * | unaffected |
Weaknesses
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://git.kernel.org/stable/c/a843925e0287eebb4aa808666bf22c664dfe4c53
- https://git.kernel.org/stable/c/0f967fdc09955221a1951a279481b0bf4d359941
- https://git.kernel.org/stable/c/80a52e1ee7757b742f96bfb0d58f0c14eb6583d0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.