PT-2025-8463 · Linux+2 · Linux Kernel+2

Keita Suzuki

·

Published

2022-04-19

·

Updated

2025-04-16

·

CVE-2022-49530

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A double free vulnerability has been identified in the Linux kernel, specifically in the si parse power table() function. This issue arises when the allocation of array members fails, leading to the array being freed and returned with an error code. However, the array is later freed again in the si dpm fini() function, which can cause a double free of the array adev->pm.dpm.ps and a leak of its array members. Additionally, the variable adev->pm.dpm.num ps is not updated until the member allocation is successfully finished, potentially leading to use after free or uninitialized variable access in si dpm fini().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01498
CVE-2022-49530
SUSE-SU-2025:1176-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Suse