CVE-2022-49881

MEDIUM

Linux Kernel <6.0.9 Use-After-Free in WiFi Regulatory Database Query

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix memory leak in query_regdb_file() In the function query_regdb_file() the alpha2 parameter is duplicated using kmemdup() and subsequently freed in regdb_fw_cb(). However, request_firmware_nowait() can fail without calling regdb_fw_cb() and thus leak memory.

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 5.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (21)
linux/Kernel 4.15.0 - 4.19.267linux
linux/Kernel 4.20.0 - 5.4.225linux
linux/Kernel 5.11.0 - 5.15.79linux
linux/Kernel 5.16.0 - 6.0.9linux
linux/Kernel 5.5.0 - 5.10.155linux
Linux/Linux < 4.15
Linux/Linux 007f6c5e6eb45c81ee89368a5f226572ae638831 - 0ede1a988299e95d54bd89551fd635980572e920
Linux/Linux 007f6c5e6eb45c81ee89368a5f226572ae638831 - 219446396786330937bcd382a7bc4ccd767383bc
Linux/Linux 007f6c5e6eb45c81ee89368a5f226572ae638831 - 38c9fa2cc6bf4b6e1a74057aef8b5cffd23d3264
Linux/Linux 007f6c5e6eb45c81ee89368a5f226572ae638831 - 57b962e627ec0ae53d4d16d7bd1033e27e67677a
... and 11 more
Published May 01, 2025
Tracked Since Feb 18, 2026