VulnerabilityModified
CVE-2022-49657
In the Linux kernel, the following vulnerability has been resolved: usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case. v2: add Fixes tag v3: fix uninitialized buf pointer
MEDIUM 5.5EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case. v2: add Fixes tag v3: fix uninitialized buf pointer
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0085da9df3dced730027923a6b48f58e9016af91Patch
- https://git.kernel.org/stable/c/04894ab34faf40ab72a8a5ab5b404bb0606bbbffPatch
- https://git.kernel.org/stable/c/3eed421ca5c809da93456f69203d164d5220be3dPatch
- https://git.kernel.org/stable/c/5269209f54dd8dfd15f9383f3a3a1fe8370764f8Patch
- https://git.kernel.org/stable/c/b55a21b764c1e182014630fa5486d717484ac58fPatch
- https://git.kernel.org/stable/c/d5165e657987ff4ba0ace896d4376a3718a9fbc3Patch
- https://git.kernel.org/stable/c/db89582ff330556188da856e01382ccbf3a5e706Patch
- https://git.kernel.org/stable/c/e7b4f69946a38209b4a4f660bf0e4cbed94f9b4bPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.