SB2025050281 - Memory leak in Linux kernel hda
Published: May 2, 2025 Updated: May 10, 2025
Security Bulletin ID
SB2025050281
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-49835)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the add_widget_node() function in sound/hda/hdac_sysfs.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/02dea987ec1cac712c78e75d224ceb9bb73519ed
- https://git.kernel.org/stable/c/3a79f9568de08657fcdbc41d6fc4c0ca145a7a2b
- https://git.kernel.org/stable/c/455d99bd6baf19688048b6d42d9fa74eae27f93b
- https://git.kernel.org/stable/c/7140d7aaf93da6a665b454f91bb4dc6b1de218bd
- https://git.kernel.org/stable/c/90b7d055e2b5f39429f9a9e3815b48a48530ef28
- https://git.kernel.org/stable/c/9a5523f72bd2b0d66eef3d58810c6eb7b5ffc143
- https://git.kernel.org/stable/c/b688a3ec235222d9a84e43a48a6f31acb95baf2d
- https://git.kernel.org/stable/c/bb0ac8d5e541224f599bc8e8f31a313faa4bf7b7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.300