CVE-2022-48958
In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_rings() function won't free the newly allocated skb when dma_mapping_error() returns error, so add…
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_rings() function won't free the newly allocated skb when dma_mapping_error() returns error, so add dev_kfree_skb() to fix it. Compile tested only.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/063a932b64db3317ec020c94466fe52923a15f60Patch
- https://git.kernel.org/stable/c/223654e2e2c8d05347cd8e300f8d1ec6023103ddPatch
- https://git.kernel.org/stable/c/87277bdf2c370ab2d07cfe77dfa9b37f82bbe1e5Patch
- https://git.kernel.org/stable/c/99669d94ce145389f1d6f197e6e18ed50d43fb76Patch
- https://git.kernel.org/stable/c/bfaa8f6c5b84b295dd73b0138b57c5555ca12b1cPatch
- https://git.kernel.org/stable/c/c7adcbd0fd3fde1b19150c3e955fb4a30c5bd9b7Patch
- https://git.kernel.org/stable/c/cb1e293f858e5e1152b8791047ed4bdaaf392189Patch
- https://git.kernel.org/stable/c/dd62867a6383f78f75f07039394aac25924a3307Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.