{"id":"DEBIAN-CVE-2022-49837","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix memory leaks in __check_func_call  kmemleak reports this issue:  unreferenced object 0xffff88817139d000 (size 2048):   comm \"test_progs\", pid 33246, jiffies 4307381979 (age 45851.820s)   hex dump (first 32 bytes):     01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................   backtrace:     [\u003c0000000045f075f0\u003e] kmalloc_trace+0x27/0xa0     [\u003c0000000098b7c90a\u003e] __check_func_call+0x316/0x1230     [\u003c00000000b4c3c403\u003e] check_helper_call+0x172e/0x4700     [\u003c00000000aa3875b7\u003e] do_check+0x21d8/0x45e0     [\u003c000000001147357b\u003e] do_check_common+0x767/0xaf0     [\u003c00000000b5a595b4\u003e] bpf_check+0x43e3/0x5bc0     [\u003c0000000011e391b1\u003e] bpf_prog_load+0xf26/0x1940     [\u003c0000000007f765c0\u003e] __sys_bpf+0xd2c/0x3650     [\u003c00000000839815d6\u003e] __x64_sys_bpf+0x75/0xc0     [\u003c00000000946ee250\u003e] do_syscall_64+0x3b/0x90     [\u003c0000000000506b7f\u003e] entry_SYSCALL_64_after_hwframe+0x63/0xcd  The root case here is: In function prepare_func_exit(), the callee is not released in the abnormal scenario after \"state-\u003ecurframe--;\". To fix, move \"state-\u003ecurframe--;\" to the very bottom of the function, right when we free callee and reset frame[] pointer to NULL, as Andrii suggested.  In addition, function __check_func_call() has a similar problem. In the abnormal scenario before \"state-\u003ecurframe++;\", the callee also should be released by free_func_state().","modified":"2026-09-01T16:05:33.450716886Z","published":"2025-05-01T15:16:07.187Z","upstream":["CVE-2022-49837"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49837"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49837.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49837.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49837.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}