cve-2022-49793
Vulnerability from cvelistv5
Published
2025-05-01 14:09
Modified
2025-05-01 14:09
Severity ?
EPSS score ?
Summary
iio: trigger: sysfs: fix possible memory leak in iio_sysfs_trig_init()
References
{ "containers": { "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "Linux", "programFiles": [ "drivers/iio/trigger/iio-trig-sysfs.c" ], "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "vendor": "Linux", "versions": [ { "lessThan": "f68c96821b61d2c71a35dbb8bf90c347fad624d9", "status": "affected", "version": "1f785681a87068f123d3e23da13b2c55ab4f93ac", "versionType": "git" }, { "lessThan": "5a39382aa5411d64b25a71516c2c7480aab13bb7", "status": "affected", "version": "1f785681a87068f123d3e23da13b2c55ab4f93ac", "versionType": "git" }, { "lessThan": "b47bb521961f027b4dcf8683337a7a1ba9e5ea1f", "status": "affected", "version": "1f785681a87068f123d3e23da13b2c55ab4f93ac", "versionType": "git" }, { "lessThan": "0dd52e141afde089304de470148d311b05c14564", "status": "affected", "version": "1f785681a87068f123d3e23da13b2c55ab4f93ac", "versionType": "git" }, { "lessThan": "8dddf2699da296c84205582aaead6b43dd7e8c4b", "status": "affected", "version": "1f785681a87068f123d3e23da13b2c55ab4f93ac", "versionType": "git" }, { "lessThan": "656f670613662b6cc77aad14112db2803ad18fa8", "status": "affected", "version": "1f785681a87068f123d3e23da13b2c55ab4f93ac", "versionType": "git" }, { "lessThan": "2c4e65285bdea23fd36d2ff376006ac64db6f42e", "status": "affected", "version": "1f785681a87068f123d3e23da13b2c55ab4f93ac", "versionType": "git" }, { "lessThan": "efa17e90e1711bdb084e3954fa44afb6647331c0", "status": "affected", "version": "1f785681a87068f123d3e23da13b2c55ab4f93ac", "versionType": "git" } ] }, { "defaultStatus": "affected", "product": "Linux", "programFiles": [ "drivers/iio/trigger/iio-trig-sysfs.c" ], "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "vendor": "Linux", "versions": [ { "status": "affected", "version": "3.0" }, { "lessThan": "3.0", "status": "unaffected", "version": "0", "versionType": "semver" }, { "lessThanOrEqual": "4.9.*", "status": "unaffected", "version": "4.9.334", "versionType": "semver" }, { "lessThanOrEqual": "4.14.*", "status": "unaffected", "version": "4.14.300", "versionType": "semver" }, { "lessThanOrEqual": "4.19.*", "status": "unaffected", "version": "4.19.267", "versionType": "semver" }, { "lessThanOrEqual": "5.4.*", "status": "unaffected", "version": "5.4.225", "versionType": "semver" }, { "lessThanOrEqual": "5.10.*", "status": "unaffected", "version": "5.10.156", "versionType": "semver" }, { "lessThanOrEqual": "5.15.*", "status": "unaffected", "version": "5.15.80", "versionType": "semver" }, { "lessThanOrEqual": "6.0.*", "status": "unaffected", "version": "6.0.10", "versionType": "semver" }, { "lessThanOrEqual": "*", "status": "unaffected", "version": "6.1", "versionType": "original_commit_for_fix" } ] } ], "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: trigger: sysfs: fix possible memory leak in iio_sysfs_trig_init()\n\ndev_set_name() allocates memory for name, it need be freed\nwhen device_add() fails, call put_device() to give up the\nreference that hold in device_initialize(), so that it can\nbe freed in kobject_cleanup() when the refcount hit to 0.\n\nFault injection test can trigger this:\n\nunreferenced object 0xffff8e8340a7b4c0 (size 32):\n comm \"modprobe\", pid 243, jiffies 4294678145 (age 48.845s)\n hex dump (first 32 bytes):\n 69 69 6f 5f 73 79 73 66 73 5f 74 72 69 67 67 65 iio_sysfs_trigge\n 72 00 a7 40 83 8e ff ff 00 86 13 c4 f6 ee ff ff r..@............\n backtrace:\n [\u003c0000000074999de8\u003e] __kmem_cache_alloc_node+0x1e9/0x360\n [\u003c00000000497fd30b\u003e] __kmalloc_node_track_caller+0x44/0x1a0\n [\u003c000000003636c520\u003e] kstrdup+0x2d/0x60\n [\u003c0000000032f84da2\u003e] kobject_set_name_vargs+0x1e/0x90\n [\u003c0000000092efe493\u003e] dev_set_name+0x4e/0x70" } ], "providerMetadata": { "dateUpdated": "2025-05-01T14:09:24.442Z", "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux" }, "references": [ { "url": "https://git.kernel.org/stable/c/f68c96821b61d2c71a35dbb8bf90c347fad624d9" }, { "url": "https://git.kernel.org/stable/c/5a39382aa5411d64b25a71516c2c7480aab13bb7" }, { "url": "https://git.kernel.org/stable/c/b47bb521961f027b4dcf8683337a7a1ba9e5ea1f" }, { "url": "https://git.kernel.org/stable/c/0dd52e141afde089304de470148d311b05c14564" }, { "url": "https://git.kernel.org/stable/c/8dddf2699da296c84205582aaead6b43dd7e8c4b" }, { "url": "https://git.kernel.org/stable/c/656f670613662b6cc77aad14112db2803ad18fa8" }, { "url": "https://git.kernel.org/stable/c/2c4e65285bdea23fd36d2ff376006ac64db6f42e" }, { "url": "https://git.kernel.org/stable/c/efa17e90e1711bdb084e3954fa44afb6647331c0" } ], "title": "iio: trigger: sysfs: fix possible memory leak in iio_sysfs_trig_init()", "x_generator": { "engine": "bippy-1.1.0" } } }, "cveMetadata": { "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "assignerShortName": "Linux", "cveId": "CVE-2022-49793", "datePublished": "2025-05-01T14:09:24.442Z", "dateReserved": "2025-05-01T14:05:17.224Z", "dateUpdated": "2025-05-01T14:09:24.442Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2022-49793\",\"sourceIdentifier\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\",\"published\":\"2025-05-01T15:16:02.563\",\"lastModified\":\"2025-05-01T15:16:02.563\",\"vulnStatus\":\"Received\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"In the Linux kernel, the following vulnerability has been resolved:\\n\\niio: trigger: sysfs: fix possible memory leak in iio_sysfs_trig_init()\\n\\ndev_set_name() allocates memory for name, it need be freed\\nwhen device_add() fails, call put_device() to give up the\\nreference that hold in device_initialize(), so that it can\\nbe freed in kobject_cleanup() when the refcount hit to 0.\\n\\nFault injection test can trigger this:\\n\\nunreferenced object 0xffff8e8340a7b4c0 (size 32):\\n comm \\\"modprobe\\\", pid 243, jiffies 4294678145 (age 48.845s)\\n hex dump (first 32 bytes):\\n 69 69 6f 5f 73 79 73 66 73 5f 74 72 69 67 67 65 iio_sysfs_trigge\\n 72 00 a7 40 83 8e ff ff 00 86 13 c4 f6 ee ff ff r..@............\\n backtrace:\\n [\u003c0000000074999de8\u003e] __kmem_cache_alloc_node+0x1e9/0x360\\n [\u003c00000000497fd30b\u003e] __kmalloc_node_track_caller+0x44/0x1a0\\n [\u003c000000003636c520\u003e] kstrdup+0x2d/0x60\\n [\u003c0000000032f84da2\u003e] kobject_set_name_vargs+0x1e/0x90\\n [\u003c0000000092efe493\u003e] dev_set_name+0x4e/0x70\"}],\"metrics\":{},\"references\":[{\"url\":\"https://git.kernel.org/stable/c/0dd52e141afde089304de470148d311b05c14564\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/2c4e65285bdea23fd36d2ff376006ac64db6f42e\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/5a39382aa5411d64b25a71516c2c7480aab13bb7\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/656f670613662b6cc77aad14112db2803ad18fa8\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/8dddf2699da296c84205582aaead6b43dd7e8c4b\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/b47bb521961f027b4dcf8683337a7a1ba9e5ea1f\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/efa17e90e1711bdb084e3954fa44afb6647331c0\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/f68c96821b61d2c71a35dbb8bf90c347fad624d9\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"}]}}" } }
Loading...
Loading...
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.