CVE-2022-49671: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fix memory leak in ib_cm_insert_listen cm_alloc_id_priv() allocates resource for the cm_id_priv. When cm_init_listen() fails it doesn't free it, leading to memory leak. Add the missing error unwind.

Affected products

  • Linux Linux Kernel: from 5.7, before 5.10.129 (fixed in 5.10.129); from 5.11, before 5.15.53 (fixed in 5.15.53); from 5.16, before 5.18.10 (fixed in 5.18.10); version 5.19 only

Published 2025-02-26. Last modified 2026-06-17.