CVE-2022-49741 describes a memory leak vulnerability in the Linux kernel's smscufx fbdev driver. Specifically, the ufx_usb_probe function contains faulty error handling logic that fails to properly deallocate memory, leading to resource exhaustion. This issue affects Linux kernel versions. The vulnerability has a CVSSv3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges and no user interaction. A successful exploit could lead to a denial of service due to memory exhaustion, impacting system availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or perceived threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.4.232CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.168CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.93CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.9.332, < 4.10CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.