CVE-2022-24959: Medium severity linux kernel vulnerability
Published Feb 11, 2022
·Updated
An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yamsiocdevprivate in drivers/net/hamradio/yam.c.
Affected Software
5 affected componentsFixes available
Linux Linux kernel<5.16.5
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
Remediation
Event History
Feb 11, 2022
CVE Published
via MITRE·04:21 AM
Data Sourced
via MITRE·04:21 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:07 AM
Description
May 6, 2025
Data Sourced
via Ubuntu·04:38 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-24959?
CVE-2022-24959 has a moderate severity due to its memory leak vulnerability in the Linux kernel.
2
How do I fix CVE-2022-24959?
To fix CVE-2022-24959, update the Linux kernel to versions 5.16.5 or later, or apply the latest patches provided by your distribution.
3
Which versions of the Linux kernel are affected by CVE-2022-24959?
CVE-2022-24959 affects the Linux kernel versions prior to 5.16.5.
4
Is CVE-2022-24959 present in Debian Linux?
Yes, CVE-2022-24959 is present in Debian Linux versions 9.0, 10.0, and 11.0 before the relevant patches are applied.
5
What types of systems are susceptible to CVE-2022-24959?
Systems running affected versions of the Linux kernel, especially those using yam_siocdevprivate in yam.c, are susceptible to CVE-2022-24959.