{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  sctp: fix memory leak in sctp_stream_outq_migrate()  When sctp_stream_outq_migrate() is called to release stream out resources, the memory pointed to by prio_head in stream out is not released.  The memory leak information is as follows:  unreferenced object 0xffff88801fe79f80 (size 64):    comm \"sctp_repo\", pid 7957, jiffies 4294951704 (age 36.480s)    hex dump (first 32 bytes):      80 9f e7 1f 80 88 ff ff 80 9f e7 1f 80 88 ff ff  ................      90 9f e7 1f 80 88 ff ff 90 9f e7 1f 80 88 ff ff  ................    backtrace:      [\u003cffffffff81b215c6\u003e] kmalloc_trace+0x26/0x60      [\u003cffffffff88ae517c\u003e] sctp_sched_prio_set+0x4cc/0x770      [\u003cffffffff88ad64f2\u003e] sctp_stream_init_ext+0xd2/0x1b0      [\u003cffffffff88aa2604\u003e] sctp_sendmsg_to_asoc+0x1614/0x1a30      [\u003cffffffff88ab7ff1\u003e] sctp_sendmsg+0xda1/0x1ef0      [\u003cffffffff87f765ed\u003e] inet_sendmsg+0x9d/0xe0      [\u003cffffffff8754b5b3\u003e] sock_sendmsg+0xd3/0x120      [\u003cffffffff8755446a\u003e] __sys_sendto+0x23a/0x340      [\u003cffffffff87554651\u003e] __x64_sys_sendto+0xe1/0x1b0      [\u003cffffffff89978b49\u003e] do_syscall_64+0x39/0xb0      [\u003cffffffff89a0008b\u003e] entry_SYSCALL_64_after_hwframe+0x63/0xcd",
  "id": "DEBIAN-CVE-2022-49013",
  "modified": "2026-09-01T19:48:15.764147306Z",
  "published": "2024-10-21T20:15:12.637Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2022-49013"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2022-49013"
  ]
}