
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-49793 is a memory leak vulnerability discovered in the Linux kernel's IIO (Industrial I/O) subsystem, specifically in the iio_sysfs_trig_init() function. The vulnerability was disclosed on May 1, 2025, affecting the Linux kernel's trigger sysfs component. The issue occurs when dev_set_name() allocates memory for a name but fails to free it when device_add() fails (NVD).
The vulnerability exists in the iio_sysfs_trig_init() function where memory allocated by dev_set_name() is not properly freed in error conditions. A fault injection test revealed this issue, showing an unreferenced object of size 32 bytes in the modprobe process. The memory leak was confirmed through backtrace analysis showing the allocation chain through _kmem_cache_alloc_node and related functions (NVD, Ubuntu).
The vulnerability results in a memory leak in the kernel space, which over time could lead to resource exhaustion. While the immediate impact per instance is small (32 bytes), repeated triggering of this condition could potentially affect system stability and performance (Wiz).
The vulnerability requires local access to trigger the memory leak condition. There are no known public exploits available for this vulnerability (Wiz).
The vulnerability has been resolved in the Linux kernel by implementing proper memory cleanup procedures. The fix involves calling put_device() to release the reference when device_add() fails, ensuring proper memory deallocation through kobject_cleanup() when the refcount reaches zero. Multiple Linux distributions have released patches, including Ubuntu which has fixed versions available for various releases (Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."