usbnet: fix memory leak in error case
Published Feb 26, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.28%
Description
usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case.
v2: add Fixes tag v3: fix uninitialized buf pointer
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.8StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.8
- Version 4.14.288StatusunaffectedConstraints<=4.14.*
- Version 4.19.252StatusunaffectedConstraints<=4.19.*
- Version 4.9.323StatusunaffectedConstraints<=4.9.*
- Version 5.10.130StatusunaffectedConstraints<=5.10.*
- Version 5.15.54StatusunaffectedConstraints<=5.15.*
- Version 5.18.11StatusunaffectedConstraints<=5.18.*
- Version 5.19StatusunaffectedConstraints<=*
- Version 5.4.205StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 3.8 · < 4.9.323
- ≥ 4.10 · < 4.14.288
- ≥ 4.15 · < 4.19.252
- ≥ 4.20 · < 5.4.205
- ≥ 5.5 · < 5.10.130
- ≥ 5.11 · < 5.15.54
- ≥ 5.16 · < 5.18.11
- 5.19
- 5.19
- 5.19
- 5.19
- 5.19
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.5.1.el9_7
Fixed · RHSA-2025:20518
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.5.1.el9_7
Fixed · RHSA-2025:20518
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.5.1.el9_7 | Fixed | RHSA-2025:20518 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.5.1.el9_7 | Fixed | RHSA-2025:20518 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The bug could happen on error path for some specific cases of network links over USB being used. It leads to memory leak only, so the security impact is limited.
Red Hat mitigation
To mitigate this issue, prevent module usbnet from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
References (13)
- https://access.redhat.com/security/cve/CVE-2022-49657 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2347707 Issue Tracking
- https://git.kernel.org/stable/c/0085da9df3dced730027923a6b48f58e9016af91 Patch
- https://git.kernel.org/stable/c/04894ab34faf40ab72a8a5ab5b404bb0606bbbff Patch
- https://git.kernel.org/stable/c/3eed421ca5c809da93456f69203d164d5220be3d Patch
- https://git.kernel.org/stable/c/5269209f54dd8dfd15f9383f3a3a1fe8370764f8 Patch
- https://git.kernel.org/stable/c/b55a21b764c1e182014630fa5486d717484ac58f Patch
- https://git.kernel.org/stable/c/d5165e657987ff4ba0ace896d4376a3718a9fbc3 Patch
- https://git.kernel.org/stable/c/db89582ff330556188da856e01382ccbf3a5e706 Patch
- https://git.kernel.org/stable/c/e7b4f69946a38209b4a4f660bf0e4cbed94f9b4b Patch
- https://lore.kernel.org/linux-cve-announce/2025022621-CVE-2022-49657-0cbf@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49657
- https://www.cve.org/CVERecord?id=CVE-2022-49657
Change history (0)
No recorded changes yet.