{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.16.7-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.16.7-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.16.7-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  KVM: x86: Free kvm_cpuid_entry2 array on post-KVM_RUN KVM_SET_CPUID{,2}  Free the \"struct kvm_cpuid_entry2\" array on successful post-KVM_RUN KVM_SET_CPUID{,2} to fix a memory leak, the callers of kvm_set_cpuid() free the array only on failure.   BUG: memory leak  unreferenced object 0xffff88810963a800 (size 2048):   comm \"syz-executor025\", pid 3610, jiffies 4294944928 (age 8.080s)   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 00 00 00 00 0d 00 00 00  ................     47 65 6e 75 6e 74 65 6c 69 6e 65 49 00 00 00 00  GenuntelineI....   backtrace:     [\u003cffffffff814948ee\u003e] kmalloc_node include/linux/slab.h:604 [inline]     [\u003cffffffff814948ee\u003e] kvmalloc_node+0x3e/0x100 mm/util.c:580     [\u003cffffffff814950f2\u003e] kvmalloc include/linux/slab.h:732 [inline]     [\u003cffffffff814950f2\u003e] vmemdup_user+0x22/0x100 mm/util.c:199     [\u003cffffffff8109f5ff\u003e] kvm_vcpu_ioctl_set_cpuid2+0x8f/0xf0 arch/x86/kvm/cpuid.c:423     [\u003cffffffff810711b9\u003e] kvm_arch_vcpu_ioctl+0xb99/0x1e60 arch/x86/kvm/x86.c:5251     [\u003cffffffff8103e92d\u003e] kvm_vcpu_ioctl+0x4ad/0x950 arch/x86/kvm/../../../virt/kvm/kvm_main.c:4066     [\u003cffffffff815afacc\u003e] vfs_ioctl fs/ioctl.c:51 [inline]     [\u003cffffffff815afacc\u003e] __do_sys_ioctl fs/ioctl.c:874 [inline]     [\u003cffffffff815afacc\u003e] __se_sys_ioctl fs/ioctl.c:860 [inline]     [\u003cffffffff815afacc\u003e] __x64_sys_ioctl+0xfc/0x140 fs/ioctl.c:860     [\u003cffffffff844a3335\u003e] do_syscall_x64 arch/x86/entry/common.c:50 [inline]     [\u003cffffffff844a3335\u003e] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80     [\u003cffffffff84600068\u003e] entry_SYSCALL_64_after_hwframe+0x44/0xae",
  "id": "DEBIAN-CVE-2022-48764",
  "modified": "2026-04-28T19:53:13.491043644Z",
  "published": "2024-06-20T12:15:14.450Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2022-48764"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2022-48764"
  ]
}