CVE-2022-49713
In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: Fix memory leak in dwc2_hcd_init usb_create_hcd will alloc memory for hcd, and we should call usb_put_hcd to free it when platform_get_resource() fails to prevent memory…
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: Fix memory leak in dwc2_hcd_init usb_create_hcd will alloc memory for hcd, and we should call usb_put_hcd to free it when platform_get_resource() fails to prevent memory leak. goto error2 label instead error1 to fix this.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/3755278f078460b021cd0384562977bf2039a57aPatch
- https://git.kernel.org/stable/c/52bfcedbfd5bf962dbdcb6e761f4d0dd3ba26dfdPatch
- https://git.kernel.org/stable/c/6506aff2dc2f7059aa3d45ee2e8639b25e87090fPatch
- https://git.kernel.org/stable/c/701d8ec01e0f229d4db6f43d3d64ee479120cbebPatch
- https://git.kernel.org/stable/c/84e6d0af87e27bbc0db94f2e7323b34abe17b6e5Patch
- https://git.kernel.org/stable/c/981ee40649e5fd9550f82db1fbb3bfab037da346Patch
- https://git.kernel.org/stable/c/a44a8a762f7fe9ad3c065813d058e835a6180cb2Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.