{"id":"CVE-2022-49105","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: wfx: fix an error handling in wfx_init_common()\n\nOne error handler of wfx_init_common() return without calling\nieee80211_free_hw(hw), which may result in memor…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: wfx: fix an error handling in wfx_init_common()\n\nOne error handler of wfx_init_common() return without calling\nieee80211_free_hw(hw), which may result in memor…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-401","CWE-401"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel < 5.10.111","linux_kernel >= 5.11, < 5.15.34","linux_kernel >= 5.16, < 5.16.20","linux_kernel >= 5.17, < 5.17.3"],"patched":["linux_kernel 5.17.3"],"published":"2025-02-26","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-49105","references":[{"url":"https://git.kernel.org/stable/c/60f1d3c92dc1ef1026e5b917a329a7fa947da036","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86efcb524ae1889ae73f2a2f0bb7fff2ec757ab0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93498c6e775ae91732a8109dba1bdcd324908f84","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9727912e906762a63c1a667c84731d3427653f88","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab0fed1fa744173433cfd1dbaf9239f200ded650","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00249,"epssPercentile":0.16577,"ingestedAt":"2026-08-13T00:57:22.314Z","slug":"CVE-2022-49105","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nstaging: wfx: fix an error handling in wfx_init_common()\n\nOne error handler of wfx_init_common() return without calling\nieee80211_free_hw(hw), which may result in memory leak. And I add\none err label to unify the error handler, which is useful for the\nsubsequent changes.\n\n## Affected\n\n- `linux_kernel < 5.10.111`\n- `linux_kernel >= 5.11, < 5.15.34`\n- `linux_kernel >= 5.16, < 5.16.20`\n- `linux_kernel >= 5.17, < 5.17.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.17.3`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}