SB2024071712 - Memory leak in Linux kernel isdn mISDN driver
Published: July 17, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-48863)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the dsp_pipeline_destroy() and dsp_pipeline_build() functions in drivers/isdn/mISDN/dsp_pipeline.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/a3d5fcc6cf2ecbba5a269631092570aa285a24cb
- https://git.kernel.org/stable/c/7777b1f795af1bb43867375d8a776080111aae1b
- https://git.kernel.org/stable/c/640445d6fc059d4514ffea79eb4196299e0e2d0f
- https://git.kernel.org/stable/c/c6a502c2299941c8326d029cfc8a3bc8a4607ad5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.106
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.29
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.15
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17