CVE-2022-49836: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: siox: fix possible memory leak in siox_device_add() If device_register() returns error in siox_device_add(), the name allocated by dev_set_name() need be freed. As comment of device_register() says, it should use put_device() to give up the reference in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanup(), and sdevice is freed in siox_device_release(), set it to null in error path.
Affected products
- Linux Linux Kernel: from 4.16, before 4.19.267 (fixed in 4.19.267); from 4.20, before 5.4.225 (fixed in 5.4.225); from 5.5, before 5.10.156 (fixed in 5.10.156); from 5.11, before 5.15.80 (fixed in 5.15.80); from 5.16, before 6.0.10 (fixed in 6.0.10); version 6.1 only
Published 2025-05-01. Last modified 2026-06-17.