CVE-2022-48724

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/06/2024
Last modified:
18/09/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iommu/vt-d: Fix potential memory leak in intel_setup_irq_remapping()<br /> <br /> After commit e3beca48a45b ("irqdomain/treewide: Keep firmware node<br /> unconditionally allocated"). For tear down scenario, fn is only freed<br /> after fail to allocate ir_domain, though it also should be freed in case<br /> dmar_enable_qi returns error.<br /> <br /> Besides free fn, irq_domain and ir_msi_domain need to be removed as well<br /> if intel_setup_irq_remapping fails to enable queued invalidation.<br /> <br /> Improve the rewinding path by add out_free_ir_domain and out_free_fwnode<br /> lables per Baolu&amp;#39;s suggestion.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.14.190 (including) 4.14.265 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.19.135 (including) 4.19.228 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.4.54 (including) 5.4.178 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.7.11 (including) 5.8 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.8 (including) 5.10.99 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.22 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.16.8 (excluding)
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*