{"id":"DEBIAN-CVE-2022-49784","details":"In the Linux kernel, the following vulnerability has been resolved:  perf/x86/amd/uncore: Fix memory leak for events array  When a CPU comes online, the per-CPU NB and LLC uncore contexts are freed but not the events array within the context structure. This causes a memory leak as identified by the kmemleak detector.    [...]   unreferenced object 0xffff8c5944b8e320 (size 32):     comm \"swapper/0\", pid 1, jiffies 4294670387 (age 151.072s)     hex dump (first 32 bytes):       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     backtrace:       [\u003c000000000759fb79\u003e] amd_uncore_cpu_up_prepare+0xaf/0x230       [\u003c00000000ddc9e126\u003e] cpuhp_invoke_callback+0x2cf/0x470       [\u003c0000000093e727d4\u003e] cpuhp_issue_call+0x14d/0x170       [\u003c0000000045464d54\u003e] __cpuhp_setup_state_cpuslocked+0x11e/0x330       [\u003c0000000069f67cbd\u003e] __cpuhp_setup_state+0x6b/0x110       [\u003c0000000015365e0f\u003e] amd_uncore_init+0x260/0x321       [\u003c00000000089152d2\u003e] do_one_initcall+0x3f/0x1f0       [\u003c000000002d0bd18d\u003e] kernel_init_freeable+0x1ca/0x212       [\u003c0000000030be8dde\u003e] kernel_init+0x11/0x120       [\u003c0000000059709e59\u003e] ret_from_fork+0x22/0x30   unreferenced object 0xffff8c5944b8dd40 (size 64):     comm \"swapper/0\", pid 1, jiffies 4294670387 (age 151.072s)     hex dump (first 32 bytes):       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     backtrace:       [\u003c00000000306efe8b\u003e] amd_uncore_cpu_up_prepare+0x183/0x230       [\u003c00000000ddc9e126\u003e] cpuhp_invoke_callback+0x2cf/0x470       [\u003c0000000093e727d4\u003e] cpuhp_issue_call+0x14d/0x170       [\u003c0000000045464d54\u003e] __cpuhp_setup_state_cpuslocked+0x11e/0x330       [\u003c0000000069f67cbd\u003e] __cpuhp_setup_state+0x6b/0x110       [\u003c0000000015365e0f\u003e] amd_uncore_init+0x260/0x321       [\u003c00000000089152d2\u003e] do_one_initcall+0x3f/0x1f0       [\u003c000000002d0bd18d\u003e] kernel_init_freeable+0x1ca/0x212       [\u003c0000000030be8dde\u003e] kernel_init+0x11/0x120       [\u003c0000000059709e59\u003e] ret_from_fork+0x22/0x30   [...]  Fix the problem by freeing the events array before freeing the uncore context.","modified":"2026-08-27T23:04:30.499468601Z","published":"2025-05-01T15:16:01.610Z","upstream":["CVE-2022-49784"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49784"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49784.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49784.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49784.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}