CVE-2022-49906: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Free rwi on reset success Free the rwi structure in the event that the last rwi in the list processed successfully. The logic in commit 4f408e1fa6e1 ("ibmvnic: retry reset if there are no other resets") introduces an issue that results in a 32 byte memory leak whenever the last rwi in the list gets processed.

Affected products

  • Linux Linux Kernel: from 5.14, before 5.15.78 (fixed in 5.15.78); from 5.16, before 6.0.8 (fixed in 6.0.8); version 6.1 only

Published 2025-05-01. Last modified 2026-06-17.