cbcvebase.
CVE-2022-48896
published 2024-08-21

CVE-2022-48896: In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix pci device refcount leak As the comment of pci_get_domain_bus_and_slot() says…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix pci device refcount leak As the comment of pci_get_domain_bus_and_slot() says, it returns a PCI device with refcount incremented, when finish using it, the caller must decrement the reference count by calling pci_dev_put(). In ixgbe_get_first_secondary_devfn() and ixgbe_x550em_a_has_mii(), pci_dev_put() is called to avoid leak.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
linuxlinux
linuxlinux>= 8fa10ef01260937eb540b4e9bbc3efa023595993 < 53cefa802f070d46c0c518f4865be2c749818a1853cefa802f070d46c0c518f4865be2c749818a18
linuxlinux>= 8fa10ef01260937eb540b4e9bbc3efa023595993 < 112df4cd2b09acd64bcd18f5ef83ba5d07b34bf0112df4cd2b09acd64bcd18f5ef83ba5d07b34bf0
linuxlinux>= 8fa10ef01260937eb540b4e9bbc3efa023595993 < 4c93422a54cd6a349988f42e1c6bf082cf4ea9d84c93422a54cd6a349988f42e1c6bf082cf4ea9d8
linuxlinux>= 8fa10ef01260937eb540b4e9bbc3efa023595993 < c49996c6aa03590e4ef5add8772cb6068d99fd59c49996c6aa03590e4ef5add8772cb6068d99fd59
linuxlinux>= 8fa10ef01260937eb540b4e9bbc3efa023595993 < b93fb4405fcb5112c5739c5349afb52ec7f15c07b93fb4405fcb5112c5739c5349afb52ec7f15c07
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 5.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.895.15.89
linuxlinux_kernel>= 5.16 < 6.1.76.1.7
linuxlinux_kernel>= 5.5 < 5.10.1645.10.164

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.