
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-49105 is a vulnerability in the Linux kernel's WFX driver that involves a memory leak in the error handling path of the wfxinitcommon() function (Kernel Git). The issue was discovered in February 2022 and affects the staging driver for WFX wireless devices.
The vulnerability occurs in the wfxinitcommon() function where an error handler returns without calling ieee80211freehw(hw), potentially resulting in a memory leak. The issue specifically manifests when the gpio_wakeup initialization fails, and the error path fails to properly clean up allocated resources (Kernel Git).
The vulnerability could lead to memory leaks in the Linux kernel when the WFX driver encounters certain error conditions during device initialization (Kernel Git).
The issue has been fixed by adding proper error handling through an 'err' label and ensuring ieee80211freehw(hw) is called in all error paths. The fix was reviewed by Dan Carpenter and Jérôme Pouiller, and committed to the Linux kernel (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."