iommu/vt-d: Fix PCI device refcount leak in dmar_dev_scope_init()
Published Oct 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
for_each_pci_dev() is implemented by pci_get_device(). The comment of pci_get_device() says that it will increase the reference count for the returned pci_dev and also decrease the reference count for the input pci_dev @from if it is not NULL.
If we break for_each_pci_dev() loop with pdev not NULL, we need to call pci_dev_put() to decrease the reference count. Add the missing pci_dev_put() for the error path to avoid reference count leak.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 3.15
Unaffected
- ≥ 0, < 3.15
- ≥ 4.14.301, ≤ 4.14.*
- ≥ 4.19.268, ≤ 4.19.*
- ≥ 4.9.335, ≤ 4.9.*
- ≥ 5.10.158, ≤ 5.10.*
- ≥ 5.15.82, ≤ 5.15.*
- ≥ 5.4.226, ≤ 5.4.*
- ≥ 6.0.12, ≤ 6.0.*
- 6.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 3.15 · < 4.9.335
- ≥ 4.10 · < 4.14.301
- ≥ 4.15 · < 4.19.268
- ≥ 4.20 · < 5.4.226
- ≥ 5.5 · < 5.10.158
- ≥ 5.11 · < 5.15.82
- ≥ 5.16 · < 6.0.12
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-49002 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320718 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53886 Advisory
- https://git.kernel.org/stable/c/2a8f7b90681472948de172dbbf5a54cd342870aa Patch
- https://git.kernel.org/stable/c/4bedbbd782ebbe7287231fea862c158d4f08a9e3 Patch
- https://git.kernel.org/stable/c/71c4a621985fc051ab86d3a86c749069a993fcb2 Patch
- https://git.kernel.org/stable/c/876d7bfb89273997056220029ff12b1c2cc4691d Patch
- https://git.kernel.org/stable/c/a5c65cd56aed027f8a97fda8b691caaeb66d115e Patch
- https://git.kernel.org/stable/c/bdb613ef179ad4bb9d56a2533e9b30e434f1dfb7 Patch
- https://git.kernel.org/stable/c/cbdd83bd2fd67142b03ce9dbdd1eab322ff7321f Patch
- https://git.kernel.org/stable/c/d47bc9d7bcdbb9adc9703513d964b514fee5b0bf Patch
- https://lore.kernel.org/linux-cve-announce/2024102150-CVE-2022-49002-5b24@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49002
- https://www.cve.org/CVERecord?id=CVE-2022-49002
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data