#VU104328 Memory leak in Linux kernel - CVE-2022-49658
Published: February 26, 2025 / Updated: May 11, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the __reg_bound_offset(), __reg_combine_32_into_64(), __reg64_bound_u32(), __reg_combine_64_into_32(), do_refine_retval_range(), adjust_ptr_min_max_vals(), adjust_scalar_min_max_vals(), check_alu_op() and __reg_combine_min_max() functions in kernel/bpf/verifier.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/3844d153a41adea718202c10ae91dc96b37453b5
- https://git.kernel.org/stable/c/a7de8d436db92bab8b1f44624297c2554a6ac36b
- https://git.kernel.org/stable/c/b2a28bb36664c94375926cbbb91976242847699d
- https://git.kernel.org/stable/c/e917be1f83ea14a68b3cf64d3da9968eaf991dae
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.130