CVE-2022-50758
In the Linux kernel, the following vulnerability has been resolved: staging: vt6655: fix potential memory leak In function device_init_td0_ring, memory is allocated for member td_info of priv->apTD0Rings[i], with i increasing from 0.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: staging: vt6655: fix potential memory leak In function device_init_td0_ring, memory is allocated for member td_info of priv->apTD0Rings[i], with i increasing from 0. In case of allocation failure, the memory is freed in reversed order, with i decreasing to 0. However, the case i=0 is left out and thus memory is leaked. Modify the memory freeing loop to include the case i=0.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.20% probability · 11th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/16a45e78a687eb6c69acc4e62b94b6508b0bfbda
- https://git.kernel.org/stable/c/1b3cebeca99e8e0aa4fa57faac8dbf41e967317a
- https://git.kernel.org/stable/c/c8ff91535880d41b49699b3829fb6151942de29e
- https://git.kernel.org/stable/c/cfdf139258614ef65b0f68b857ada5328fb7c0e5
- https://git.kernel.org/stable/c/e741e38aa98704fbb959650ecd270b71b2670680
- https://git.kernel.org/stable/c/fb5f569bcda8f87bd47d8030bfae343d757fa3ea
- https://git.kernel.org/stable/c/ff8551d411f12b5abc5ca929ab87643afa8a9588
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.