CVE-2022-49923

medium

Description

In the Linux kernel, the following vulnerability has been resolved: nfc: nxp-nci: Fix potential memory leak in nxp_nci_send() nxp_nci_send() will call nxp_nci_i2c_write(), and only free skb when nxp_nci_i2c_write() failed. However, even if the nxp_nci_i2c_write() run succeeds, the skb will not be freed in nxp_nci_i2c_write(). As the result, the skb will memleak. nxp_nci_send() should also free the skb when nxp_nci_i2c_write() succeeds.

References

https://git.kernel.org/stable/c/9ae2c9a91ff068f4c3e392f47e8e26a1c9f85ebb

https://git.kernel.org/stable/c/7bf1ed6aff0f70434bd0cdd45495e83f1dffb551

https://git.kernel.org/stable/c/3ecf0f4227029b2c42e036b10ff6e5d09e20821e

https://git.kernel.org/stable/c/3cba1f061bfe23fece2841129ca2862cdec29d5c

Details

Source: Mitre, NVD

Published: 2025-05-01

Updated: 2025-05-07

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00018