video: fbdev: amba-clcd: Fix refcount leak bugs
Published Jun 18, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
In clcdfb_of_init_display(), we should call of_node_put() for the references returned by of_graph_get_next_endpoint() and of_graph_get_remote_port_parent() which have increased the refcount.
Besides, we should call of_node_put() both in fail path or when the references are not used anymore.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.17StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.17
- Version 4.14.291StatusunaffectedConstraints<=4.14.*
- Version 4.19.256StatusunaffectedConstraints<=4.19.*
- Version 5.10.137StatusunaffectedConstraints<=5.10.*
- Version 5.15.61StatusunaffectedConstraints<=5.15.*
- Version 5.18.18StatusunaffectedConstraints<=5.18.*
- Version 5.19.2StatusunaffectedConstraints<=5.19.*
- Version 5.4.211StatusunaffectedConstraints<=5.4.*
- Version 6.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 3.17 · < 4.14.291
- ≥ 4.15 · < 4.19.256
- ≥ 4.20 · < 5.4.211
- ≥ 5.5 · < 5.10.137
- ≥ 5.11 · < 5.15.61
- ≥ 5.16 · < 5.18.18
- ≥ 5.19 · < 5.19.2
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (13)
- https://access.redhat.com/security/cve/CVE-2022-50109 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2373558 Issue Tracking
- https://git.kernel.org/stable/c/2688df86c02da6bdc9866b62d974e169a2678883 Patch
- https://git.kernel.org/stable/c/26c2b7d9fac42eb8317f3ceefa4c1a9a9170ca69 Patch
- https://git.kernel.org/stable/c/29f06f1905c312671a09ee85ca92ac04a1d9f305 Patch
- https://git.kernel.org/stable/c/49a4c1a87ef884e43cdda58b142a2a30f2f09efc Patch
- https://git.kernel.org/stable/c/a51519ebd0fdad3546463018b8f6bc3b0f4d3032 Patch
- https://git.kernel.org/stable/c/a88ab277cca99aeb9a3b2b7db358f1a6dd528b0c Patch
- https://git.kernel.org/stable/c/a97ff8a949dbf41be89f436b2b1a2b3d794493df Patch
- https://git.kernel.org/stable/c/da276dc288bf838ea0fd778b5441ec0f601c69f7 Patch
- https://lore.kernel.org/linux-cve-announce/2025061807-CVE-2022-50109-9f52@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50109
- https://www.cve.org/CVERecord?id=CVE-2022-50109
Change history (0)
No recorded changes yet.