CVE-2022-49996: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix possible memory leak in btrfs_get_dev_args_from_path() In btrfs_get_dev_args_from_path(), btrfs_get_bdev_and_sb() can fail if the path is invalid. In this case, btrfs_get_dev_args_from_path() returns directly without freeing args->uuid and args->fsid allocated before, which causes memory leak. To fix these possible leaks, when btrfs_get_bdev_and_sb() fails, btrfs_put_dev_args_from_path() is called to clean up the memory.

Affected products

  • Linux Linux Kernel: from 5.15.54, before 5.15.64 (fixed in 5.15.64); from 5.16, before 5.19.6 (fixed in 5.19.6); version 6.0 only

Published 2025-06-18. Last modified 2026-06-17.