CVE-2022-49793
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49793 is a memory leak vulnerability discovered in the Linux kernel's IIO (Industrial I/O) subsystem, specifically in the iiosysfstriginit() function. The vulnerability was disclosed on May 1, 2025, affecting the Linux kernel's trigger sysfs component. The issue occurs when devsetname() allocates memory for a name but fails to free it when deviceadd() fails (NVD).

Technical details

The vulnerability exists in the iiosysfstriginit() function where memory allocated by devsetname() is not properly freed in error conditions. A fault injection test revealed this issue, showing an unreferenced object of size 32 bytes in the modprobe process. The memory leak was confirmed through backtrace analysis showing the allocation chain through kmemcachealloc_node and related functions (NVD, Ubuntu).

Impact

The vulnerability results in a memory leak in the kernel space, which over time could lead to resource exhaustion. While the immediate impact per instance is small (32 bytes), repeated triggering of this condition could potentially affect system stability and performance (Wiz).

Mitigation and workarounds

The vulnerability has been resolved in the Linux kernel by implementing proper memory cleanup procedures. The fix involves calling putdevice() to release the reference when deviceadd() fails, ensuring proper memory deallocation through kobject_cleanup() when the refcount reaches zero. Multiple Linux distributions have released patches, including Ubuntu which has fixed versions available for various releases (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management