device property: fix of node refcount leak in fwnode_graph_get_next_endpoint()
Published Mar 27, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.20%
Description
The 'parent' returned by fwnode_graph_get_port_parent() with refcount incremented when 'prev' is not NULL, it needs be put when finish using it.
Because the parent is const, introduce a new variable to store the returned fwnode, then put it before returning from fwnode_graph_get_next_endpoint().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.15
- Version 5.15.91StatusunaffectedConstraints<=5.15.*
- Version 6.1.9StatusunaffectedConstraints<=6.1.*
- Version 6.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.15 · < 5.15.91
- ≥ 5.16 · < 6.1.9
- 6.2
- 6.2
- 6.2
- 6.2
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-49752 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2355453 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55171 Advisory
- https://git.kernel.org/stable/c/39af728649b05e88a2b40e714feeee6451c3f18e Patch
- https://git.kernel.org/stable/c/7701a4bd45c11f9a289d8f262fad05705a012339 Patch
- https://git.kernel.org/stable/c/e0472947bead3af94cc968ce35fc0414803a2f65
- https://git.kernel.org/stable/c/e75485fc589ec729cc182aa9b41dfb6c15ae6f6e Patch
- https://lore.kernel.org/linux-cve-announce/2025032700-CVE-2022-49752-19a3@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49752
- https://www.cve.org/CVERecord?id=CVE-2022-49752
Change history (0)
No recorded changes yet.