PT-2025-8463 · Linux+2 · Linux Kernel+2
Keita Suzuki
·
Published
2022-04-19
·
Updated
2025-04-16
·
CVE-2022-49530
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A double free vulnerability has been identified in the Linux kernel, specifically in the
si parse power table() function. This issue arises when the allocation of array members fails, leading to the array being freed and returned with an error code. However, the array is later freed again in the si dpm fini() function, which can cause a double free of the array adev->pm.dpm.ps and a leak of its array members. Additionally, the variable adev->pm.dpm.num ps is not updated until the member allocation is successfully finished, potentially leading to use after free or uninitialized variable access in si dpm fini().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse