CVE-2022-49206: RDMA/mlx5: Fix memory leak in error flow for subscribe event routine
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mlx5: Fix memory leak in error flow for subscribe event routine
In case the second xa_insert() fails, the obj_event is not released. Fix
the error unwind flow to free that memory to avoid a memory leak.
Security readout for executives and security teams
Plain-English summary
CVE-2022-49206 is a Linux kernel memory leak in the Mellanox mlx5 RDMA driver error path. A local user with low privileges may be able to affect availability by consuming kernel memory under vulnerable conditions. The provided sources do not show data theft, integrity impact, remote attack, or active exploitation.
Executive priority
Treat this as a routine availability-risk kernel update, not an emergency internet-facing exposure. Prioritize shared compute, HPC, virtualization, or storage environments where local users and RDMA hardware are present, then roll into normal kernel maintenance after vendor confirmation.
Technical view
The issue is CWE-401 in RDMA/mlx5 event subscription handling. If the second xa_insert() fails, obj_event is not released during error unwind, leaking memory. CVSS 3.1 is 5.5: local attack vector, low complexity, low privileges, no user interaction, high availability impact only.
Likely exposure
Exposure is most relevant to Linux systems running affected kernel versions with the mlx5 RDMA driver path present. The source bundle lists Linux 5.3 through 5.18-related affected entries and fixed stable commits, but exact distribution package mapping must be confirmed with vendor advisories.
Exploitation context
CISA KEV is false in the provided bundle, and no cited source states active exploitation. The CVSS vector indicates exploitation requires local access and low privileges. Practical risk is availability disruption rather than confidentiality or integrity compromise.
Researcher notes
The public description is narrow: a missing free in an RDMA/mlx5 error path after a failed second xa_insert(). Evidence supports memory leak and availability impact only. No exploit details, proof of concept, or temporary mitigation are provided in the bundle.
Mitigation direction
Apply a vendor kernel update containing the referenced Linux stable fixes.
Check distribution advisories for exact fixed package versions.
Prioritize systems using Mellanox mlx5 RDMA functionality.
If no update is available, request vendor guidance for temporary risk reduction.
Validation and detection
Inventory running kernel versions on Linux hosts.
Identify hosts using mlx5 RDMA-capable hardware or drivers.
Check kernel package changelogs for the referenced stable commits.
Confirm scanners map distribution backports correctly before marking hosts vulnerable.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-401: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.