CVE-2022-49461

MEDIUM

Linux Kernel 5.16-5.17.13, 5.18.0-5.18.2 - Use-After-Free in AMT Advertisement Handler

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: amt: fix memory leak for advertisement message When a gateway receives an advertisement message, it extracts relay information and then it should be freed. But the advertisement handler doesn't free it. So, memory leak would occur.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (11)
linux/Kernel 5.16.0 - 5.17.14linux
linux/Kernel 5.18.0 - 5.18.3linux
Linux/Linux < 5.16
Linux/Linux 5.16
Linux/Linux 5.17.14 - 5.17.*
Linux/Linux 5.18.3 - 5.18.*
Linux/Linux 5.19
Linux/Linux cbc21dc1cfe949e37b2a54c71511579f1899e8d4 - 19bb2d57eac86a368839a92117d8a10ab7183623
Linux/Linux cbc21dc1cfe949e37b2a54c71511579f1899e8d4 - e7322da399fb86a2072f008b56f7160afa1b2051
Linux/Linux cbc21dc1cfe949e37b2a54c71511579f1899e8d4 - fe29794c3585d039fefebaa2b5a4932a627ad4fd
... and 1 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026