
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-48880 affects the Linux kernel's platform/surface aggregator component. The vulnerability was discovered in the ssamrequestsync() function where a memory leak occurs when ssamrequestsyncinit() fails, as the request is not properly freed via ssamrequestsyncfree(). This issue was fixed in the Linux kernel through a patch that adds the missing call to ssamrequestsync_free() (Kernel Commit).
The vulnerability exists in the Surface Aggregator subsystem's controller code. When ssamrequestsyncinit() fails, which is a rare occurrence, the request should be freed using ssamrequestsyncfree(). However, the original code failed to perform this cleanup, resulting in a memory leak. The issue was introduced in commit c167b9c7e3d6 which added the Surface Aggregator subsystem (Kernel Commit).
The vulnerability results in a memory leak in the Linux kernel when certain error conditions occur in the Surface Aggregator subsystem. While the condition is described as rare, repeated occurrences could lead to resource exhaustion over time (Kernel Commit).
The issue has been fixed by adding the missing call to ssamrequestsyncfree() when ssamrequestsyncinit() fails. The fix was implemented in commit c965daac370f08a9b71d573a71d13cda76f2a884 and has been backported to stable kernel versions. Users should update their Linux kernel to a version containing this fix (Kernel Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."