CVE-2022-49230
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a memory leak vulnerability (CVE-2022-49230) was identified in the mt7915mcuadd_sta routine. The issue occurs when allocated skb (socket buffer) is not properly freed in case of failures. This vulnerability affects the MediaTek MT76 wireless driver, specifically the MT7915 chipset implementation (Kernel Git).

Technical details

The vulnerability stems from missing cleanup code in error handling paths within the mt7915mcuaddsta function. When certain operations like mt7915mcustawtbltlv() or mt7915mcuaddgroup() fail, the allocated socket buffer (skb) is not properly freed before returning, leading to memory leaks. The fix involves adding proper cleanup code by calling devkfreeskb() in the error paths (Kernel Git).

Impact

The memory leak can lead to gradual system memory depletion over time as socket buffers are not properly freed when errors occur in the wireless driver. This could potentially result in degraded system performance or stability issues in systems using the affected MT7915 wireless hardware.

Mitigation and workarounds

The vulnerability has been fixed by adding proper cleanup code in the error handling paths. The fix ensures that allocated socket buffers are freed when operations fail. Users should update their Linux kernel to a version containing the fix, which was implemented in commit a43736cd12d82913102eb49cb56787a5553e028f (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-devel
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-trace
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-headers
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management