cbcvebase.
CVE-2022-49346
published 2025-02-26

CVE-2022-49346: In the Linux kernel, the following vulnerability has been resolved: net: dsa: lantiq_gswip: Fix refcount leak in gswip_gphy_fw_list Every iteration of…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net: dsa: lantiq_gswip: Fix refcount leak in gswip_gphy_fw_list Every iteration of for_each_available_child_of_node() decrements the reference count of the previous node. when breaking early from a for_each_available_child_of_node() loop, we need to explicitly call of_node_put() on the gphy_fw_np. Add missing of_node_put() to avoid refcount leak.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 14fceff4771e51b23b4485b575cf9e5b3414b89b < 7c8df6fad43d9d5d77f281f794b2a93cd02fd1a97c8df6fad43d9d5d77f281f794b2a93cd02fd1a9
linuxlinux>= 14fceff4771e51b23b4485b575cf9e5b3414b89b < c2ae49a113a5344232f1ebb93bcf18bbd11e9c39c2ae49a113a5344232f1ebb93bcf18bbd11e9c39
linuxlinux>= 14fceff4771e51b23b4485b575cf9e5b3414b89b < 54d6802c4d83fa8de7696cfec06f475d5fd92d2754d6802c4d83fa8de7696cfec06f475d5fd92d27
linuxlinux>= 14fceff4771e51b23b4485b575cf9e5b3414b89b < 32cd78c5610f02a929f63cac985e73692d05f33e32cd78c5610f02a929f63cac985e73692d05f33e
linuxlinux>= 14fceff4771e51b23b4485b575cf9e5b3414b89b < 2e007ac6fa7c9c94ad84da075c5c504afad690a02e007ac6fa7c9c94ad84da075c5c504afad690a0
linuxlinux>= 14fceff4771e51b23b4485b575cf9e5b3414b89b < 0737e018a05e2aa352828c52bdeed3b02cff29300737e018a05e2aa352828c52bdeed3b02cff2930
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.475.15.47
linuxlinux_kernel>= 5.16 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4
linuxlinux_kernel>= 5.5 < 5.10.1225.10.122

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.