Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-48753

Description

In the Linux kernel, the following vulnerability has been resolved:block: fix memory leak in disk_register_independent_access_rangeskobject_init_and_add() takes reference even when it fails.According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object.Fix this issue by adding kobject_put().Callback function blk_ia_ranges_sysfs_release() in kobject_put()can handle the pointer "iars" properly.

POC

Reference

- https://git.kernel.org/stable/c/fe4214a07e0b53d2af711f57519e33739c5df23f

Github

No PoCs found on GitHub currently.