#VU104287 Memory leak in Linux kernel - CVE-2022-49462


Vulnerability identifier: #VU104287

Vulnerability risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-49462

CWE-ID: CWE-401

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the a6xx_gpu_init() function in drivers/gpu/drm/msm/adreno/a6xx_gpu.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/06907a374f1b74f8f2fb30720dc6df81331e4fb5
https://git.kernel.org/stable/c/48e82ce8cdb19c20a5020fa446b286d6a147450c
https://git.kernel.org/stable/c/65ddbc0d26824e2a5d6154d01d8cf39344900213
https://git.kernel.org/stable/c/6832e36f156ea35a6ed74bca72727806116effdd
https://git.kernel.org/stable/c/c56de483093d7ad0782327f95dda7da97bc4c315
https://git.kernel.org/stable/c/edff4c1af831d0c02e654eed9da7d74174de49d5


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability