PT-2024-11880 · Linux+4 · Linux Kernel+4
Wang Hai
·
Published
2022-11-28
·
Updated
2025-09-29
·
CVE-2022-49020
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A potential socket leak issue has been identified in the Linux kernel, specifically in the
p9 socket open function within the net/9p module. The issue arises when p9 fd create tcp() and p9 fd create unix() call p9 socket open() and the creation of p9 trans fd fails, leading to an error being returned directly without releasing the socket, thus causing a socket leak. The problem is resolved by adding sock release() to address the leak.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Release of Resource after Effective Lifetime
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linux Kernel
Red Os
Suse