
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-50321 is a memory leak vulnerability discovered in the Linux kernel's brcmfmac WiFi driver component. The issue was identified in the brcmf_netdev_start_xmit() function, which returns NETDEV_TX_OK without properly freeing the skb (socket buffer) when pskb_expand_head() fails (NVD).
The vulnerability exists in the brcmf_netdev_start_xmit() function of the Linux kernel's brcmfmac WiFi driver. When pskb_expand_head() fails, the function returns NETDEV_TX_OK without freeing the socket buffer (skb), leading to a potential memory leak. The fix involves adding dev_kfree_skb() to properly free the memory when the failure occurs (NVD).
The vulnerability can lead to memory leaks in the Linux kernel when using the brcmfmac WiFi driver. While it can lead to gradual resource exhaustion under repeated error conditions, the impact appears to be limited to memory resource consumption (Red Hat).
The vulnerability has been patched in various Linux distributions. Ubuntu has released fixes for multiple versions including Ubuntu 22.04 LTS (5.15.0-75.82), 20.04 LTS (5.4.0-152.169), and various kernel variants for cloud platforms (Ubuntu). Users are advised to update their systems to the patched versions.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."