CVE-2022-48928

MEDIUM

Linux Kernel Use-After-Free in IIO ADC Driver

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: iio: adc: men_z188_adc: Fix a resource leak in an error handling path If iio_device_register() fails, a previous ioremap() is left unbalanced. Update the error handling path and add the missing iounmap() call, as already done in the remove function.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (26)
linux/Kernel 3.15.0 - 4.9.304linux
linux/Kernel 4.10.0 - 4.14.269linux
linux/Kernel 4.15.0 - 4.19.232linux
linux/Kernel 4.20.0 - 5.4.182linux
linux/Kernel 5.11.0 - 5.15.26linux
linux/Kernel 5.16.0 - 5.16.12linux
linux/Kernel 5.5.0 - 5.10.103linux
Linux/Linux < 3.15
Linux/Linux 3.15
Linux/Linux 4.14.269 - 4.14.*
... and 16 more
Published Aug 22, 2024
Tracked Since Feb 18, 2026