CVE-2022-49144

MEDIUM

Linux Kernel 5.5-5.10.110, 5.11-5.15.33, 5.16-5.16.19, 5.17-5.17.2 - Use-After-Free in io_uring Files Registration

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix memory leak of uid in files registration When there are no files for __io_sqe_files_scm() to process in the range, it'll free everything and return. However, it forgets to put uid.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 15.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (17)
linux/Kernel 5.11.0 - 5.15.33linux
linux/Kernel 5.16.0 - 5.16.19linux
linux/Kernel 5.17.0 - 5.17.2linux
linux/Kernel 5.5.0 - 5.10.110linux
Linux/Linux < 5.5
Linux/Linux 08a451739a9b5783f67de51e84cb6d9559bb9dc4 - 0853bd6885c2f293d88aaa7f7f1702c959b31680
Linux/Linux 08a451739a9b5783f67de51e84cb6d9559bb9dc4 - 7fa8b228c3f30060b9f4b24bb9aaaf41b0ae83fe
Linux/Linux 08a451739a9b5783f67de51e84cb6d9559bb9dc4 - b27de7011cb3ba14b047be2cee0ed8278368665b
Linux/Linux 08a451739a9b5783f67de51e84cb6d9559bb9dc4 - c86d18f4aa93e0e66cda0e55827cd03eea6bc5f8
Linux/Linux 08a451739a9b5783f67de51e84cb6d9559bb9dc4 - d6d7a517e81accf6ed22d55684baea763d2dbe43
... and 7 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026