PT-2025-8147 · Linux+3 · Linux Kernel+3
Published
2022-01-01
·
Updated
2025-05-25
·
CVE-2022-49219
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory leak issue has been identified in the Linux kernel, specifically in the vfio/pci component. The leak occurs during the transition from D3hot to D0 power state when the
vfio pci core device::needs pm restore flag is set. This happens because the pci load and free saved state() function, which is responsible for freeing the allocated memory, is not called in certain situations, such as when the guest resumes after a reset-related IOCTL. An attacker could exploit this by repeatedly triggering the state change to D3hot followed by a VFIO DEVICE RESET or VFIO DEVICE PCI HOT RESET, potentially leading to an out-of-memory (OOM) situation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linux Kernel
Suse