CVE-2022-49113
published 2025-02-26CVE-2022-49113: In the Linux kernel, the following vulnerability has been resolved: powerpc/secvar: fix refcount leak in format_show() Refcount leak will happen when…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
powerpc/secvar: fix refcount leak in format_show()
Refcount leak will happen when format_show returns failure in multiple
cases. Unified management of of_node_put can fix this problem.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= bd5d9c743d38f67d64ea1b512a461f6b5a5f6bec < 02222bf4f0a27f6eba66d1f597cdb5daadd51829 | 02222bf4f0a27f6eba66d1f597cdb5daadd51829 |
| linux | linux | >= bd5d9c743d38f67d64ea1b512a461f6b5a5f6bec < 2a71e3ecd829a82013cf095c55068c61d991e885 | 2a71e3ecd829a82013cf095c55068c61d991e885 |
| linux | linux | >= bd5d9c743d38f67d64ea1b512a461f6b5a5f6bec < c105ffb6b9744158e37e9f81f0f38861951d1c1f | c105ffb6b9744158e37e9f81f0f38861951d1c1f |
| linux | linux | >= bd5d9c743d38f67d64ea1b512a461f6b5a5f6bec < d05e4265d33af60b39606c20c731e3e719bfe3d6 | d05e4265d33af60b39606c20c731e3e719bfe3d6 |
| linux | linux | >= bd5d9c743d38f67d64ea1b512a461f6b5a5f6bec < d601fd24e6964967f115f036a840f4f28488f63f | d601fd24e6964967f115f036a840f4f28488f63f |
| linux | linux_kernel | < 5.10.111 | 5.10.111 |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 5.11 < 5.15.34 | 5.15.34 |
| linux | linux_kernel | >= 5.16 < 5.16.20 | 5.16.20 |
| linux | linux_kernel | >= 5.17 < 5.17.3 | 5.17.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: powerpc/secvar: fix refcount leak in format_show()
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49113 [MEDIUM] CWE-401 kernel: powerpc/secvar: fix refcount leak in format_show()
kernel: powerpc/secvar: fix refcount leak in format_show()
In the Linux kernel, the following vulnerability has been resolved:
powerpc/secvar: fix refcount leak in format_show()
Refcount leak will happen when format_show returns failure in multiple
cases. Unified management of of_node_put can fix this problem.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 8) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterpri
Debian
CVE-2022-49113: linux - In the Linux kernel, the following vulnerability has been resolved: powerpc/sec...
vendor_debian·2022·CVSS 5.5
CVE-2022-49113 [MEDIUM] CVE-2022-49113: linux - In the Linux kernel, the following vulnerability has been resolved: powerpc/sec...
In the Linux kernel, the following vulnerability has been resolved: powerpc/secvar: fix refcount leak in format_show() Refcount leak will happen when format_show returns failure in multiple cases. Unified management of of_node_put can fix this problem.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.17.3-1)
GHSA
GHSA-6gvx-3255-6x8r: In the Linux kernel, the following vulnerability has been resolved:
powerpc/secvar: fix refcount leak in format_show()
Refcount leak will happen whe
ghsa_unreviewed·2025-03-14
CVE-2022-49113 [MEDIUM] GHSA-6gvx-3255-6x8r: In the Linux kernel, the following vulnerability has been resolved:
powerpc/secvar: fix refcount leak in format_show()
Refcount leak will happen whe
In the Linux kernel, the following vulnerability has been resolved:
powerpc/secvar: fix refcount leak in format_show()
Refcount leak will happen when format_show returns failure in multiple
cases. Unified management of of_node_put can fix this problem.
OSV
CVE-2022-49113: In the Linux kernel, the following vulnerability has been resolved: powerpc/secvar: fix refcount leak in format_show() Refcount leak will happen when
osv·2025-02-26·CVSS 5.5
CVE-2022-49113 [MEDIUM] CVE-2022-49113: In the Linux kernel, the following vulnerability has been resolved: powerpc/secvar: fix refcount leak in format_show() Refcount leak will happen when
In the Linux kernel, the following vulnerability has been resolved: powerpc/secvar: fix refcount leak in format_show() Refcount leak will happen when format_show returns failure in multiple cases. Unified management of of_node_put can fix this problem.
Suricata
ET EXPLOIT Microsoft LDAP Referral Response Inbound (CVE-2024-49113)
suricata·2025-01-07·CVSS 7.5
CVE-2024-49113 [HIGH] ET EXPLOIT Microsoft LDAP Referral Response Inbound (CVE-2024-49113)
ET EXPLOIT Microsoft LDAP Referral Response Inbound (CVE-2024-49113)
Rule: alert udp $EXTERNAL_NET 389 -> $HOME_NET any (msg:"ET EXPLOIT Microsoft LDAP Referral Response Inbound (CVE-2024-49113)"; content:"|30|"; depth:1; content:"|04|"; distance:2; within:1; content:"|65|"; distance:4; within:1; content:"|0a 01|"; distance:1; within:2; content:"|a3|"; distance:0; content:"ldap"; within:7; pcre:"/^s?\x3a\x2f{2}/R"; reference:url,www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49113/; reference:cve,2024-49113; classtype:attempted-dos; sid:2059017; rev:1; metadata:affected_product Windows_11, affected_product Windows_Server_2019, affected_product Windows_Server_2022, affected_product Windows_Server_2016, affected_product Windows_10
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/02222bf4f0a27f6eba66d1f597cdb5daadd51829https://git.kernel.org/stable/c/2a71e3ecd829a82013cf095c55068c61d991e885https://git.kernel.org/stable/c/c105ffb6b9744158e37e9f81f0f38861951d1c1fhttps://git.kernel.org/stable/c/d05e4265d33af60b39606c20c731e3e719bfe3d6https://git.kernel.org/stable/c/d601fd24e6964967f115f036a840f4f28488f63f
2025-02-26
Published