CVE-2022-49283

MEDIUM

Linux Kernel 5.15-5.15.32, 5.16-5.16.18, 5.17 - Use-After-Free in sysfb Platform Device Registration

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: firmware: sysfb: fix platform-device leak in error path Make sure to free the platform device also in the unlikely event that registration fails.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (14)
linux/Kernel 5.15.0 - 5.15.33linux
linux/Kernel 5.16.0 - 5.16.19linux
linux/Kernel 5.17.0 - 5.17.2linux
Linux/Linux < 5.15
Linux/Linux 5.15
Linux/Linux 5.15.33 - 5.15.*
Linux/Linux 5.16.19 - 5.16.*
Linux/Linux 5.17.2 - 5.17.*
Linux/Linux 5.18
Linux/Linux 8633ef82f101c040427b57d4df7b706261420b94 - 202c08914ba50dd324e42d5ad99535a89f242560
... and 4 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026