PT-2025-8441 · Linux+2 · Linux Kernel+2

Miaoqian Lin

·

Published

2025-02-26

·

Updated

2025-04-15

·

CVE-2022-49508

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential double free issue in the elan input configured function of the Linux kernel's HID (Human Interface Device) elan driver has been resolved. The issue arises because the input resource, allocated with devm input allocate device(), is freed explicitly with input free device(), leading to a double free. According to the documentation of devm input allocate device(), managed input devices are automatically unregistered and freed when the owner device unbinds from its driver, making explicit unregistration or freeing unnecessary.
Recommendations For the affected Linux kernel versions, consider updating to a version that includes the fix for the double free issue in the elan input configured function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-49508
OESA-2025-1336
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Astra Linux
Linux Kernel
Suse