cbcvebase.
CVE-2022-49212
published 2025-02-26

CVE-2022-49212: In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: atmel: fix refcount issue in atmel_nand_controller_init The reference…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: atmel: fix refcount issue in atmel_nand_controller_init The reference counting issue happens in several error handling paths on a refcounted object "nc->dmac". In these paths, the function simply returns the error code, forgetting to balance the reference count of "nc->dmac", increased earlier by dma_request_channel(), which may cause refcount leaks. Fix it by decrementing the refcount of specific object in those error paths.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= f88fc122cc34c2545dec9562eaab121494e401ef < 0856bf27057561f42b37df111603cf5a0d0402940856bf27057561f42b37df111603cf5a0d040294
linuxlinux>= f88fc122cc34c2545dec9562eaab121494e401ef < 9843c9c98f26c6ad843260b19bfdaa2598f2ae1e9843c9c98f26c6ad843260b19bfdaa2598f2ae1e
linuxlinux>= f88fc122cc34c2545dec9562eaab121494e401ef < 9b08d211db4c447eb1a07df65e45e0aa772e0fa69b08d211db4c447eb1a07df65e45e0aa772e0fa6
linuxlinux>= f88fc122cc34c2545dec9562eaab121494e401ef < a3587259ae553e41d1ce8c7435351a5d6b299a11a3587259ae553e41d1ce8c7435351a5d6b299a11
linuxlinux>= f88fc122cc34c2545dec9562eaab121494e401ef < fe0e2ce5c87e9c0b9485ff566362030aa55972cffe0e2ce5c87e9c0b9485ff566362030aa55972cf
linuxlinux>= f88fc122cc34c2545dec9562eaab121494e401ef < 8baea2b96fa90af8d0f937caf4cf2105ee094d938baea2b96fa90af8d0f937caf4cf2105ee094d93
linuxlinux>= f88fc122cc34c2545dec9562eaab121494e401ef < f1694169f3674cdf7553aed06864254635679878f1694169f3674cdf7553aed06864254635679878
linuxlinux>= f88fc122cc34c2545dec9562eaab121494e401ef < fecbd4a317c95d73c849648c406bcf1b6a0ec1cffecbd4a317c95d73c849648c406bcf1b6a0ec1cf
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.12 < 4.14.2764.14.276
linuxlinux_kernel>= 4.15 < 4.19.2384.19.238
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.