PT-2025-8147 · Linux+3 · Linux Kernel+3

Published

2022-01-01

·

Updated

2025-05-25

·

CVE-2022-49219

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue has been identified in the Linux kernel, specifically in the vfio/pci component. The leak occurs during the transition from D3hot to D0 power state when the vfio pci core device::needs pm restore flag is set. This happens because the pci load and free saved state() function, which is responsible for freeing the allocated memory, is not called in certain situations, such as when the guest resumes after a reset-related IOCTL. An attacker could exploit this by repeatedly triggering the state change to D3hot followed by a VFIO DEVICE RESET or VFIO DEVICE PCI HOT RESET, potentially leading to an out-of-memory (OOM) situation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-49219
DLA-4178-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Debian
Linux Kernel
Suse