CVE-2022-49566

Summary

In the Linux kernel, the following vulnerability has been resolved:

crypto: qat - fix memory leak in RSA

When an RSA key represented in form 2 (as defined in PKCS #1 V2.1) is used, some components of the private key persist even after the TFM is released. Replace the explicit calls to free the buffers in qat_rsa_exit_tfm() with a call to qat_rsa_clear_ctx() which frees all buffers referenced in the TFM context.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux879f77e9071f029e1c9bd5a75814ecf51370f846 < a843925e0287eebb4aa808666bf22c664dfe4c53affected
LinuxLinux879f77e9071f029e1c9bd5a75814ecf51370f846 < 0f967fdc09955221a1951a279481b0bf4d359941affected
LinuxLinux879f77e9071f029e1c9bd5a75814ecf51370f846 < 80a52e1ee7757b742f96bfb0d58f0c14eb6583d0affected
LinuxLinux4.8affected
LinuxLinux0 < 4.8unaffected
LinuxLinux5.15.58 <= 5.15.*unaffected
LinuxLinux5.18.15 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References