CVE-2022-49306

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: host: Stop setting the ACPI companion It is no longer needed. The sysdev pointer is now used when assigning the ACPI companions to the xHCI ports and USB devices. Assigning the ACPI companion here resulted in the fwnode->secondary pointer to be replaced also for the parent dwc3 device since the primary fwnode (the ACPI companion) was shared. That was unintentional and it created potential side effects like resource leaks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Oct 2025, 11:45

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: usb: dwc3: host: Detener la configuración del compañero ACPI Ya no es necesario. El puntero sysdev ahora se utiliza al asignar los compañeros ACPI a los puertos xHCI y dispositivos USB. Asignar el compañero ACPI aquí resultó en que el puntero fwnode->secondary también se reemplazara para el dispositivo dwc3 principal ya que el fwnode primario (el compañero ACPI) se compartía. Eso no fue intencional y creó posibles efectos secundarios como fugas de recursos.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/7fd069d65da2e20b1caec3b7bcf9dfbe28c04bb2 - () https://git.kernel.org/stable/c/7fd069d65da2e20b1caec3b7bcf9dfbe28c04bb2 - Patch
References () https://git.kernel.org/stable/c/9c185fde906a48368bd2d2a8c17d4b6fb3d670af - () https://git.kernel.org/stable/c/9c185fde906a48368bd2d2a8c17d4b6fb3d670af - Patch
References () https://git.kernel.org/stable/c/d7f35934f7ab67bfd9adabc84207e59da9c19108 - () https://git.kernel.org/stable/c/d7f35934f7ab67bfd9adabc84207e59da9c19108 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

26 Feb 2025, 07:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:01

Updated : 2025-10-21 11:45


NVD link : CVE-2022-49306

Mitre link : CVE-2022-49306

CVE.ORG link : CVE-2022-49306


JSON object : View

Products Affected

linux

  • linux_kernel