ocxl: fix pci device refcount leak when calling get_function_0()
Published Sep 15, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
get_function_0() calls pci_get_domain_bus_and_slot(), as comment says, it returns a pci device with refcount increment, so after using it, pci_dev_put() needs be called.
Get the device reference when get_function_0() is not called, so pci_dev_put() can be called in the error path and callers unconditionally. And add comment above get_dvsec_vendor0() to tell callers to call pci_dev_put().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.9StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.9
- Version 5.10.163StatusunaffectedConstraints<=5.10.*
- Version 5.15.86StatusunaffectedConstraints<=5.15.*
- Version 6.0.16StatusunaffectedConstraints<=6.0.*
- Version 6.1.2StatusunaffectedConstraints<=6.1.*
- Version 6.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.9 · < 5.10.163
- ≥ 5.11 · < 5.15.86
- ≥ 5.16 · < 6.0.16
- ≥ 6.1 · < 6.1.2
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-50337 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2395355 Issue Tracking
- https://git.kernel.org/stable/c/27158c72678b39ee01cc01de1aba6b51c71abe2f Patch
- https://git.kernel.org/stable/c/37a13b274e4513c757e50c002ddcbf4bc89adbb2 Patch
- https://git.kernel.org/stable/c/40ff4c2335a98f0ee96b099bfd70b8e6644f321f Patch
- https://git.kernel.org/stable/c/9a1b3148975b71fdc194e62612478346bbe618cd Patch
- https://git.kernel.org/stable/c/a40e1b0a922a53fa925ea8b296e3de30a31ed028 Patch
- https://lore.kernel.org/linux-cve-announce/2025091556-CVE-2022-50337-42aa@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50337
- https://www.cve.org/CVERecord?id=CVE-2022-50337
Change history (0)
No recorded changes yet.