SB20250226157 - Memory leak in Linux kernel iio adc driver
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-49683)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the adi_axi_adc_attach_client() function in drivers/iio/adc/adi-axi-adc.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/501652a2ad5450b4908e1f204ce75b2414c305b7
- https://git.kernel.org/stable/c/5eaa84e1605035a90a64d25b6cba79e89d188175
- https://git.kernel.org/stable/c/ab7bf025cee89db73c649216ddd2bc589c3d3862
- https://git.kernel.org/stable/c/ada7b0c0dedafd7d059115adf49e48acba3153a8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.127
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.51
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19