CVE-2022-49370

Source
https://cve.org/CVERecord?id=CVE-2022-49370
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49370.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49370
Downstream
Related
Published
2025-02-26T02:11:13.176Z
Modified
2026-04-11T12:43:57.062655Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
firmware: dmi-sysfs: Fix memory leak in dmi_sysfs_register_handle
Details

In the Linux kernel, the following vulnerability has been resolved:

firmware: dmi-sysfs: Fix memory leak in dmisysfsregister_handle

kobjectinitandadd() takes reference even when it fails. According to the doc of kobjectinitandadd()

If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object.

Fix this issue by calling kobject_put().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49370.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
948af1f0bbc8526448e8cbe3f8d3bf211bdf5181
Fixed
a9bfb37d6ba7c376b0d53337a4c5f5ff324bd725
Fixed
ed38d04342dfbe9e5aca745c8b5eb4188a74f0ef
Fixed
c66cc3c62870a27ea8f060a7e4c1ad8d26dd3f0d
Fixed
a724634b2a49f6ff0177a9e19a5a92fc1545e1b7
Fixed
985706bd3bbeffc8737bc05965ca8d24837bc7db
Fixed
fdffa4ad8f6bf1ece877edfb807f2b2c729d8578
Fixed
3ba359ebe914ac3f8c6c832b28007c14c39d3766
Fixed
ec752973aa721ee281d5441e497364637c626c7b
Fixed
660ba678f9998aca6db74f2dd912fa5124f0fa31

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49370.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.39
Fixed
4.9.318
Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
4.14.283
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.247
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.198
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.122
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.47
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.17.15
Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
5.18.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49370.json"