cbcvebase.
CVE-2022-49386
published 2025-02-26

CVE-2022-49386: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix some refcount leaks of_get_child_by_name() returns a…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix some refcount leaks of_get_child_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. am65_cpsw_init_cpts() and am65_cpsw_nuss_probe() don't release the refcount in error case. Add missing of_node_put() to avoid refcount leak.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 93a76530316a3d8cc2d82c3deca48424fee92100 < f7ba2cc57f404d2d9f26fb85bd3833d35a477829f7ba2cc57f404d2d9f26fb85bd3833d35a477829
linuxlinux>= 93a76530316a3d8cc2d82c3deca48424fee92100 < a4b7ef3b159805ba6be061d0cd2403d84b9b0063a4b7ef3b159805ba6be061d0cd2403d84b9b0063
linuxlinux>= 93a76530316a3d8cc2d82c3deca48424fee92100 < 78aca10a16f001c9f49f1cc4dadfee8d444bb17378aca10a16f001c9f49f1cc4dadfee8d444bb173
linuxlinux>= 93a76530316a3d8cc2d82c3deca48424fee92100 < 2e44f21c384503562713b7d3b673c40bed20af3d2e44f21c384503562713b7d3b673c40bed20af3d
linuxlinux>= 93a76530316a3d8cc2d82c3deca48424fee92100 < 5dd89d2fc438457811cbbec07999ce0d80051ff55dd89d2fc438457811cbbec07999ce0d80051ff5
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 5.11 < 5.15.475.15.47
linuxlinux_kernel>= 5.16 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4
linuxlinux_kernel>= 5.7 < 5.10.1225.10.122

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.