CVE-2022-49793
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49793 is a memory leak vulnerability discovered in the Linux kernel's IIO (Industrial I/O) subsystem, specifically in the iio_sysfs_trig_init() function. The vulnerability was disclosed on May 1, 2025, affecting the Linux kernel's trigger sysfs component. The issue occurs when dev_set_name() allocates memory for a name but fails to free it when device_add() fails (NVD).

Technical details

The vulnerability exists in the iio_sysfs_trig_init() function where memory allocated by dev_set_name() is not properly freed in error conditions. A fault injection test revealed this issue, showing an unreferenced object of size 32 bytes in the modprobe process. The memory leak was confirmed through backtrace analysis showing the allocation chain through _kmem_cache_alloc_node and related functions (NVD, Ubuntu).

Impact

The vulnerability results in a memory leak in the kernel space, which over time could lead to resource exhaustion. While the immediate impact per instance is small (32 bytes), repeated triggering of this condition could potentially affect system stability and performance (Wiz).

Exploitability

The vulnerability requires local access to trigger the memory leak condition. There are no known public exploits available for this vulnerability (Wiz).

Mitigation and workarounds

The vulnerability has been resolved in the Linux kernel by implementing proper memory cleanup procedures. The fix involves calling put_device() to release the reference when device_add() fails, ensuring proper memory deallocation through kobject_cleanup() when the refcount reaches zero. Multiple Linux distributions have released patches, including Ubuntu which has fixed versions available for various releases (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management