cbcvebase.
CVE-2022-49389
published 2025-02-26

CVE-2022-49389: In the Linux kernel, the following vulnerability has been resolved: usb: usbip: fix a refcount leak in stub_probe() usb_get_dev() is called in…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.4th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: usbip: fix a refcount leak in stub_probe() usb_get_dev() is called in stub_device_alloc(). When stub_probe() fails after that, usb_put_dev() needs to be called to release the reference. Fix this by moving usb_put_dev() to sdev_free error path handling. Find this by code review.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.16.58 < 3.173.17
linuxlinux>= 3.18.110 < 3.193.19
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < 6bafee2f18af5e5ac125e42960bc65496d0e56a06bafee2f18af5e5ac125e42960bc65496d0e56a0
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < f20d2d3b3364ce6525c050a8b6b4c54c8c19674df20d2d3b3364ce6525c050a8b6b4c54c8c19674d
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < 247d3809e45a34d9e1a3a2bb7012e31ed8b46031247d3809e45a34d9e1a3a2bb7012e31ed8b46031
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < 2f0ae93ec33c8456cdfbf7876b80403a6318ebce2f0ae93ec33c8456cdfbf7876b80403a6318ebce
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < bcbb795a9e78180d74c6ab21518da87e803dfdcebcbb795a9e78180d74c6ab21518da87e803dfdce
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < 51422046be504515eb5a591adf0f424b62f4680451422046be504515eb5a591adf0f424b62f46804
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < 8afb048800919d0ab10c57983940eba956339f218afb048800919d0ab10c57983940eba956339f21
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < 11c65408bd0ba1d9cd1307caa38169292de9cdfb11c65408bd0ba1d9cd1307caa38169292de9cdfb
linuxlinux>= 3ff67445750a84de67faaf52c6e1895cb09f2c56 < 9ec4cbf1cc55d126759051acfe328d489c5d6e609ec4cbf1cc55d126759051acfe328d489c5d6e60
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 3.16.58 < 3.173.17
linuxlinux_kernel>= 3.18.110 < 4.9.3184.9.318
linuxlinux_kernel>= 4.10 < 4.14.2834.14.283
linuxlinux_kernel>= 4.15 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.475.15.47

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.