CVE-2022-49480

In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-hdmi: Fix refcount leak in imx_hdmi_probe of_find_device_by_node() takes reference, we should use put_device() to release it. when devm_kzalloc() fails, it doesn't have a put_device(), it will cause refcount leak. Add missing put_device() to fix this.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

17 Mar 2025, 16:53

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/81b7edaabd44ba133006ad72056914eb36828d60 - () https://git.kernel.org/stable/c/81b7edaabd44ba133006ad72056914eb36828d60 - Patch
References () https://git.kernel.org/stable/c/8205a0114db10ec41bd2b748cdd7528632082eca - () https://git.kernel.org/stable/c/8205a0114db10ec41bd2b748cdd7528632082eca - Patch
References () https://git.kernel.org/stable/c/cf760e494ee5fa6bc2dc222f0098c741ad460801 - () https://git.kernel.org/stable/c/cf760e494ee5fa6bc2dc222f0098c741ad460801 - Patch
References () https://git.kernel.org/stable/c/ed46731d8e86c8d65f5fc717671e1f1f6c3146d2 - () https://git.kernel.org/stable/c/ed46731d8e86c8d65f5fc717671e1f1f6c3146d2 - Patch
First Time Linux linux Kernel
Linux
CWE NVD-CWE-Other
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ASoC: imx-hdmi: se corrige la pérdida de recuento de referencias en imx_hdmi_probe. La referencia que toma la instancia de_find_device_by_node() se debe liberar. Deberíamos usar put_device() para liberarla. Cuando falla devm_kzalloc(), no tiene un put_device(), lo que provocará una pérdida de recuento de referencias. Agregue el put_device() faltante para solucionar esto.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

26 Feb 2025, 07:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:01

Updated : 2025-03-17 16:53


NVD link : CVE-2022-49480

Mitre link : CVE-2022-49480

CVE.ORG link : CVE-2022-49480


JSON object : View

Products Affected

linux

  • linux_kernel