From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D73921ADC5 for ; Wed, 26 Feb 2025 02:24:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740536692; cv=none; b=CfdPFyxovT3uPI6019g63e48NxOHbWMJWi4HHyzraUFHSe+3GuYmF08tk8dBv+mnA9eULxaS+hM/oUcm71z9AnF3nGz0e4YsWadjNxWHTZLgYmLWxYw1okEmO/uqwuwqs8HgFu6T7Deju9K12sZ5mEmwO+/+ARnjvAaF8cL+0SM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740536692; c=relaxed/simple; bh=Dm8UEEhQZttRXFBi7XzrQb6TDJGJDtaWQdk2ulozyVc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=AoM56Uzg2C7ufusDWazKHqHC4rvRxqlGy8ed4oJibEOzuq4H+P65fmTq9HkfidHyRTrK3hUNRNE2SKz8t6Tgh1EhqITClHdT3kwAO9i0r0WAyS0hqjw3qmcMzISGHDYhwdRAly1leynYfNkFSxJXUoF6tl50xzaarN5LsnVpahU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=MXSUArST; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="MXSUArST" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 621DFC4CEDD; Wed, 26 Feb 2025 02:24:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1740536692; bh=Dm8UEEhQZttRXFBi7XzrQb6TDJGJDtaWQdk2ulozyVc=; h=From:To:Cc:Subject:Date:Reply-to:From; b=MXSUArSTpYt5IyrhBrT/yNshXRdP3c8OZ2F6cv8V8LEZ9SEp43K+gvB7eOO7vVA6M P9Yw9r2Oum7VwSX65cNGATfH5lf8IjQmjr4mMjCj+d5xmKj6lgpqh6UD8a7RulghYa CYSvcybpAL5K2a2Z4rX1ck6lwyztiZWSzD884hMY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2022-49657: usbnet: fix memory leak in error case Date: Wed, 26 Feb 2025 03:23:40 +0100 Message-ID: <2025022621-CVE-2022-49657-0cbf@gregkh> X-Mailer: git-send-email 2.48.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=3257; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Dm8UEEhQZttRXFBi7XzrQb6TDJGJDtaWQdk2ulozyVc=; b=owGbwMvMwCRo6H6F97bub03G02pJDOn7qu5+k1f6uGTTQvPYFnuuaIb5r8N+XFy5tKF1j3vDX 74Df1b2dsSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEsuYwzOHr8fNt/bDsr6lW LmO0jVG8KZ/0Qob5oRwzA5LunFuXPTHlxW8p1cOz/v+YDAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case. v2: add Fixes tag v3: fix uninitialized buf pointer The Linux kernel CVE team has assigned CVE-2022-49657 to this issue. Affected and fixed versions =========================== Issue introduced in 3.8 with commit 877bd862f32b815d54ab5fc10a4fd903d7bf3012 and fixed in 4.9.323 with commit 3eed421ca5c809da93456f69203d164d5220be3d Issue introduced in 3.8 with commit 877bd862f32b815d54ab5fc10a4fd903d7bf3012 and fixed in 4.14.288 with commit 5269209f54dd8dfd15f9383f3a3a1fe8370764f8 Issue introduced in 3.8 with commit 877bd862f32b815d54ab5fc10a4fd903d7bf3012 and fixed in 4.19.252 with commit d5165e657987ff4ba0ace896d4376a3718a9fbc3 Issue introduced in 3.8 with commit 877bd862f32b815d54ab5fc10a4fd903d7bf3012 and fixed in 5.4.205 with commit 04894ab34faf40ab72a8a5ab5b404bb0606bbbff Issue introduced in 3.8 with commit 877bd862f32b815d54ab5fc10a4fd903d7bf3012 and fixed in 5.10.130 with commit 0085da9df3dced730027923a6b48f58e9016af91 Issue introduced in 3.8 with commit 877bd862f32b815d54ab5fc10a4fd903d7bf3012 and fixed in 5.15.54 with commit db89582ff330556188da856e01382ccbf3a5e706 Issue introduced in 3.8 with commit 877bd862f32b815d54ab5fc10a4fd903d7bf3012 and fixed in 5.18.11 with commit e7b4f69946a38209b4a4f660bf0e4cbed94f9b4b Issue introduced in 3.8 with commit 877bd862f32b815d54ab5fc10a4fd903d7bf3012 and fixed in 5.19 with commit b55a21b764c1e182014630fa5486d717484ac58f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2022-49657 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/usb/usbnet.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/3eed421ca5c809da93456f69203d164d5220be3d https://git.kernel.org/stable/c/5269209f54dd8dfd15f9383f3a3a1fe8370764f8 https://git.kernel.org/stable/c/d5165e657987ff4ba0ace896d4376a3718a9fbc3 https://git.kernel.org/stable/c/04894ab34faf40ab72a8a5ab5b404bb0606bbbff https://git.kernel.org/stable/c/0085da9df3dced730027923a6b48f58e9016af91 https://git.kernel.org/stable/c/db89582ff330556188da856e01382ccbf3a5e706 https://git.kernel.org/stable/c/e7b4f69946a38209b4a4f660bf0e4cbed94f9b4b https://git.kernel.org/stable/c/b55a21b764c1e182014630fa5486d717484ac58f