CVE-2022-49391

HIGH

Linux Kernel 5.18-5.18.3 - Double Free in remoteproc mtk_scp

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: remoteproc: mtk_scp: Fix a potential double free 'scp->rproc' is allocated using devm_rproc_alloc(), so there is no need to free it explicitly in the remove function.

Scores

CVSS v3 7.8
EPSS 0.0023
EPSS Percentile 13.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-415
Status published
Products (8)
linux/Kernel 5.18.0 - 5.18.4linux
Linux/Linux < 5.18
Linux/Linux 5.18
Linux/Linux 5.18.4 - 5.18.*
Linux/Linux 5.19
Linux/Linux c1407ac1099ab9726c31d38d806f3150f494c494 - adc02700236613b344a947a897fc2741d52a43b9
Linux/Linux c1407ac1099ab9726c31d38d806f3150f494c494 - eac3e5b1c12f85732e60f5f8b985444d273866bb
linux/linux_kernel 5.18 - 5.18.4
Published Feb 26, 2025
Tracked Since Feb 18, 2026