gianfar: ethtool: Fix refcount leak in gfar_get_ts_info
Published Jul 16, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
The of_find_compatible_node() function returns a node pointer with refcount incremented, We should use of_node_put() on it when done Add the missing of_node_put() to release the refcount.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.18StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.18
- Version 4.19.235StatusunaffectedConstraints<=4.19.*
- Version 5.10.106StatusunaffectedConstraints<=5.10.*
- Version 5.15.29StatusunaffectedConstraints<=5.15.*
- Version 5.16.15StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version 5.4.185StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.18 · < 4.19.235
- ≥ 4.20 · < 5.4.185
- ≥ 5.5 · < 5.10.106
- ≥ 5.11 · < 5.15.29
- ≥ 5.16 · < 5.16.15
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-48856 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298197 Issue Tracking
- https://git.kernel.org/stable/c/0e1b9a2078e07fb1e6e91bf8badfd89ecab1e848 Patch
- https://git.kernel.org/stable/c/21044e679ed535345042d2023f7df0ca8e897e2a Patch
- https://git.kernel.org/stable/c/2ac5b58e645c66932438bb021cb5b52097ce70b0 Patch
- https://git.kernel.org/stable/c/6263f2eb93a85ad7df504daf0c341a7fb6bbe8a6 Patch
- https://git.kernel.org/stable/c/f49f646f9ec296fc0afe7ae92c2bb47f23e3846c Patch
- https://git.kernel.org/stable/c/f7b3b520349193f8a82cca74daf366199e06add9 Patch
- https://lore.kernel.org/linux-cve-announce/2024071626-CVE-2022-48856-fd52@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48856
- https://www.cve.org/CVERecord?id=CVE-2022-48856
Change history (0)
No recorded changes yet.