CVE-2022-49881
MEDIUMLinux Kernel <6.0.9 Use-After-Free in WiFi Regulatory Database Query
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix memory leak in query_regdb_file() In the function query_regdb_file() the alpha2 parameter is duplicated using kmemdup() and subsequently freed in regdb_fw_cb(). However, request_firmware_nowait() can fail without calling regdb_fw_cb() and thus leak memory.
References (6)
Core 6
Core References
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
5.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (21)
linux/Kernel
4.15.0 - 4.19.267linux
linux/Kernel
4.20.0 - 5.4.225linux
linux/Kernel
5.11.0 - 5.15.79linux
linux/Kernel
5.16.0 - 6.0.9linux
linux/Kernel
5.5.0 - 5.10.155linux
Linux/Linux
< 4.15
Linux/Linux
007f6c5e6eb45c81ee89368a5f226572ae638831 - 0ede1a988299e95d54bd89551fd635980572e920
Linux/Linux
007f6c5e6eb45c81ee89368a5f226572ae638831 - 219446396786330937bcd382a7bc4ccd767383bc
Linux/Linux
007f6c5e6eb45c81ee89368a5f226572ae638831 - 38c9fa2cc6bf4b6e1a74057aef8b5cffd23d3264
Linux/Linux
007f6c5e6eb45c81ee89368a5f226572ae638831 - 57b962e627ec0ae53d4d16d7bd1033e27e67677a
... and 11 more
Published
May 01, 2025
Tracked Since
Feb 18, 2026