CVE-2022-49148
Published: Feb 26, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: watch_queue: Free the page array when watch_queue is dismantled Commit 7ea1a0124b6d ("watch_queue: Free the alloc bitmap when the watch_queue is torn down") took care of the bitmap, but not the page array. BUG: memory leak unreferenced object 0xffff88810d9bc140 (size 32): comm "syz-executor335", pid 3603, jiffies 4294946994 (age 12.840s) hex dump (first 32 bytes): 40 a7 40 04 00 ea ff ff 00 00 00 00 00 00 00 00 @.@............. 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: kmalloc_array include/linux/slab.h:621 [inline] kcalloc include/linux/slab.h:652 [inline] watch_queue_set_size+0x12f/0x2e0 kernel/watch_queue.c:251 pipe_ioctl+0x82/0x140 fs/pipe.c:632 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:874 [inline] __se_sys_ioctl fs/ioctl.c:860 [inline] __x64_sys_ioctl+0xfc/0x140 fs/ioctl.c:860 do_syscall_x64 arch/x86/entry/common.c:50 [inline]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected c73be61cede5882f9605a852414db559c0ebedfd - < 7169f60110915c8b53bffd43741fa020a75eb87aaffected c73be61cede5882f9605a852414db559c0ebedfd - < 4913daecd04addb41bc96a9175a885e1c19862a8affected c73be61cede5882f9605a852414db559c0ebedfd - < 3963a5d1ff75585bddf0c3a918566a6be09d7520affected c73be61cede5882f9605a852414db559c0ebedfd - < 375cd2536494cfbcdda84ae8b3e35bf19d0250b9affected c73be61cede5882f9605a852414db559c0ebedfd - < b490207017ba237d97b735b2aa66dc241ccd18f5 |
Linux | Linux | affected 5.8unaffected 0 - < 5.8unaffected 5.10.110 - <= 5.10.*unaffected 5.15.33 - <= 5.15.*unaffected 5.16.19 - <= 5.16.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now