ixgbe: fix pci device refcount leak
Published Aug 21, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.24%
Description
As the comment of pci_get_domain_bus_and_slot() says, it returns a PCI device with refcount incremented, when finish using it, the caller must decrement the reference count by calling pci_dev_put().
In ixgbe_get_first_secondary_devfn() and ixgbe_x550em_a_has_mii(), pci_dev_put() is called to avoid leak.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.0
Unaffected
- ≥ 0, < 5.0
- ≥ 5.10.164, ≤ 5.10.*
- ≥ 5.15.89, ≤ 5.15.*
- ≥ 5.4.229, ≤ 5.4.*
- ≥ 6.1.7, ≤ 6.1.*
- 6.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 5.0 · < 5.4.229
- ≥ 5.5 · < 5.10.164
- ≥ 5.11 · < 5.15.89
- ≥ 5.16 · < 6.1.7
- 6.2
- 6.2
- 6.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-48896 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2306417 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53775 Advisory
- https://git.kernel.org/stable/c/112df4cd2b09acd64bcd18f5ef83ba5d07b34bf0 Patch
- https://git.kernel.org/stable/c/4c93422a54cd6a349988f42e1c6bf082cf4ea9d8 Patch
- https://git.kernel.org/stable/c/53cefa802f070d46c0c518f4865be2c749818a18 Patch
- https://git.kernel.org/stable/c/b93fb4405fcb5112c5739c5349afb52ec7f15c07 Patch
- https://git.kernel.org/stable/c/c49996c6aa03590e4ef5add8772cb6068d99fd59 Patch
- https://lore.kernel.org/linux-cve-announce/2024082110-CVE-2022-48896-7c80@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48896
- https://www.cve.org/CVERecord?id=CVE-2022-48896
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data