CVE-2022-49213

Summary

In the Linux kernel, the following vulnerability has been resolved:

ath10k: Fix error handling in ath10k_setup_msa_resources

The device_node pointer is returned by of_parse_phandle() with refcount incremented. We should use of_node_put() on it when done.

This function only calls of_node_put() in the regular path. And it will cause refcount leak in error path.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux727fec790ead3d75e2735f66209949c2163523ea < 315772133a4b960859e4f5efe0e738e347188cdcaffected
LinuxLinux727fec790ead3d75e2735f66209949c2163523ea < 32939187f254171a5666badc058bc3787fe454afaffected
LinuxLinux727fec790ead3d75e2735f66209949c2163523ea < 74b1d41e1b6410eed5c76d00eedb262036e9eff5affected
LinuxLinux727fec790ead3d75e2735f66209949c2163523ea < 4ed37d611ea5d222c3ecb3549e4c2d34b8f3c335affected
LinuxLinux727fec790ead3d75e2735f66209949c2163523ea < 9747a78d5f758a5284751a10aee13c30d02bd5f1affected
LinuxLinux5.8affected
LinuxLinux0 < 5.8unaffected
LinuxLinux5.10.110 <= 5.10.*unaffected
LinuxLinux5.15.33 <= 5.15.*unaffected
LinuxLinux5.16.19 <= 5.16.*unaffected
LinuxLinux5.17.2 <= 5.17.*unaffected
LinuxLinux5.18 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References