CVE-2022-48768: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: tracing/histogram: Fix a potential memory leak for kstrdup() kfree() is missing on an error path to free the memory allocated by kstrdup(): p = param = kstrdup(data->params[i], GFP_KERNEL); So it is better to free it via kfree(p).
Affected products
- Linux Linux Kernel: from 5.4.19, before 5.4.176 (fixed in 5.4.176); from 5.6, before 5.10.96 (fixed in 5.10.96); from 5.11, before 5.15.19 (fixed in 5.15.19); from 5.16, before 5.16.5 (fixed in 5.16.5); version 5.17 only
Published 2024-06-20. Last modified 2026-06-17.