CVE-2022-48753

In the Linux kernel, the following vulnerability has been resolved: block: fix memory leak in disk_register_independent_access_ranges kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix this issue by adding kobject_put(). Callback function blk_ia_ranges_sysfs_release() in kobject_put() can handle the pointer "iars" properly.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*

History

18 Sep 2024, 16:03

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-401
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: bloque: corrige la pérdida de memoria en disk_register_independent_access_ranges kobject_init_and_add() toma referencia incluso cuando falla. Según el documento de kobject_init_and_add() Si esta función devuelve un error, se debe llamar a kobject_put() para limpiar adecuadamente la memoria asociada con el objeto. Solucione este problema agregando kobject_put(). La función de devolución de llamada blk_ia_ranges_sysfs_release() en kobject_put() puede manejar el puntero "iars" correctamente.
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/83114df32ae779df57e0af99a8ba6c3968b2ba3d - () https://git.kernel.org/stable/c/83114df32ae779df57e0af99a8ba6c3968b2ba3d - Patch
References () https://git.kernel.org/stable/c/fe4214a07e0b53d2af711f57519e33739c5df23f - () https://git.kernel.org/stable/c/fe4214a07e0b53d2af711f57519e33739c5df23f - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

20 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-20 12:15

Updated : 2024-09-18 16:03


NVD link : CVE-2022-48753

Mitre link : CVE-2022-48753

CVE.ORG link : CVE-2022-48753


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime