CVE-2022-48924

MEDIUM

Linux Kernel Use-After-Free in int3400_notify

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: fix memory leak in int3400_notify() It is easy to hit the below memory leaks in my TigerLake platform: unreferenced object 0xffff927c8b91dbc0 (size 32): comm "kworker/0:2", pid 112, jiffies 4294893323 (age 83.604s) hex dump (first 32 bytes): 4e 41 4d 45 3d 49 4e 54 33 34 30 30 20 54 68 65 NAME=INT3400 The 72 6d 61 6c 00 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b a5 rmal.kkkkkkkkkk. backtrace: [<ffffffff9c502c3e>] __kmalloc_track_caller+0x2fe/0x4a0 [<ffffffff9c7b7c15>] kvasprintf+0x65/0xd0 [<ffffffff9c7b7d6e>] kasprintf+0x4e/0x70 [<ffffffffc04cb662>] int3400_notify+0x82/0x120 [int3400_thermal] [<ffffffff9c8b7358>] acpi_ev_notify_dispatch+0x54/0x71 [<ffffffff9c88f1a7>] acpi_os_execute_deferred+0x17/0x30 [<ffffffff9c2c2c0a>] process_one_work+0x21a/0x3f0 [<ffffffff9c2c2e2a>] worker_thread+0x4a/0x3b0 [<ffffffff9c2cb4dd>] kthread+0xfd/0x130 [<ffffffff9c201c1f>] ret_from_fork+0x1f/0x30 Fix it by calling kfree() accordingly.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (23)
linux/Kernel 4.14.0 - 4.14.274linux
linux/Kernel 4.15.0 - 4.19.237linux
linux/Kernel 4.20.0 - 5.4.188linux
linux/Kernel 5.11.0 - 5.15.26linux
linux/Kernel 5.16.0 - 5.16.12linux
linux/Kernel 5.5.0 - 5.10.103linux
Linux/Linux < 4.14
Linux/Linux 38e44da591303d08b0d965a033e11ade284999d0 - 2e798814e01827871938ff172d2b2ccf1e74b355
Linux/Linux 38e44da591303d08b0d965a033e11ade284999d0 - 33c73a4d7e7b19313a6b417152f5365016926418
Linux/Linux 38e44da591303d08b0d965a033e11ade284999d0 - 3abea10e6a8f0e7804ed4c124bea2d15aca977c8
... and 13 more
Published Aug 22, 2024
Tracked Since Feb 18, 2026