CVE-2022-49508

Source
https://cve.org/CVERecord?id=CVE-2022-49508
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49508.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49508
Downstream
Related
Published
2025-02-26T02:13:39.472Z
Modified
2026-04-11T12:44:08.972814Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
HID: elan: Fix potential double free in elan_input_configured
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: elan: Fix potential double free in elaninputconfigured

'input' is a managed resource allocated with devminputallocatedevice(), so there is no need to call inputfree_device() explicitly or there will be a double free.

According to the doc of devminputallocate_device(): * Managed input devices do not need to be explicitly unregistered or * freed as it will be done automatically when owner device unbinds from * its driver (or binding fails).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49508.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9a6a4193d65b853020ef0e66cecdf9e64a863883
Fixed
c92ec22a991778a096342cf1a917ae36c5c86a90
Fixed
f1d4f19a796551edc6679a681ea1756b8c578c08
Fixed
6d0726725c7c560495f5ff364862a2cefea542e3
Fixed
24f9dfdaece9bd75bb8dbfdba83eddeefdf7dc47
Fixed
5291451851feeb66fd4bf0826710f482f3b1ab38
Fixed
8bb1716507ebf12d50bbf181764481de3b6bc7fd
Fixed
1af20714fedad238362571620be0bd690ded05b6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49508.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
4.19.247
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.198
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.121
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.46
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.17.14
Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
5.18.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49508.json"