CVE-2022-49396
published 2025-02-26CVE-2022-49396: In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp: fix reset-controller leak on probe errors Make sure to release the lane…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
phy: qcom-qmp: fix reset-controller leak on probe errors
Make sure to release the lane reset controller in case of a late probe
error (e.g. probe deferral).
Note that due to the reset controller being defined in devicetree in
"lane" child nodes, devm_reset_control_get_exclusive() cannot be used
directly.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= e78f3d15e115e8e764d4b1562b4fa538f2e22f6b < b7b5fbcaac5355e2e695dc0c08a0fcf248250388 | b7b5fbcaac5355e2e695dc0c08a0fcf248250388 |
| linux | linux | >= e78f3d15e115e8e764d4b1562b4fa538f2e22f6b < a39d9eccb333b8c07c43ebea1c6dfda122378a0f | a39d9eccb333b8c07c43ebea1c6dfda122378a0f |
| linux | linux | >= e78f3d15e115e8e764d4b1562b4fa538f2e22f6b < 7ac21b24af859c097eb4034e93430056068f8f31 | 7ac21b24af859c097eb4034e93430056068f8f31 |
| linux | linux | >= e78f3d15e115e8e764d4b1562b4fa538f2e22f6b < 2156dc390402043ba5982489c6625adcb0b0975c | 2156dc390402043ba5982489c6625adcb0b0975c |
| linux | linux | >= e78f3d15e115e8e764d4b1562b4fa538f2e22f6b < ba173a6f8d8dffed64bb13ab23081bdddfb464f0 | ba173a6f8d8dffed64bb13ab23081bdddfb464f0 |
| linux | linux | >= e78f3d15e115e8e764d4b1562b4fa538f2e22f6b < feb05b10b3ed3ae21b851520a0d0b71685439517 | feb05b10b3ed3ae21b851520a0d0b71685439517 |
| linux | linux | >= e78f3d15e115e8e764d4b1562b4fa538f2e22f6b < 8c03eb0c8982677b4e17174073a011788891304d | 8c03eb0c8982677b4e17174073a011788891304d |
| linux | linux | >= e78f3d15e115e8e764d4b1562b4fa538f2e22f6b < 4d2900f20edfe541f75756a00deeb2ffe7c66bc1 | 4d2900f20edfe541f75756a00deeb2ffe7c66bc1 |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 4.12 < 4.14.283 | 4.14.283 |
| linux | linux_kernel | >= 4.15 < 4.19.247 | 4.19.247 |
| linux | linux_kernel | >= 4.20 < 5.4.198 | 5.4.198 |
| linux | linux_kernel | >= 5.11 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
| linux | linux_kernel | >= 5.5 < 5.10.121 | 5.10.121 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: phy: qcom-qmp: fix reset-controller leak on probe errors
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49396 [MEDIUM] kernel: phy: qcom-qmp: fix reset-controller leak on probe errors
kernel: phy: qcom-qmp: fix reset-controller leak on probe errors
In the Linux kernel, the following vulnerability has been resolved:
phy: qcom-qmp: fix reset-controller leak on probe errors
Make sure to release the lane reset controller in case of a late probe
error (e.g. probe deferral).
Note that due to the reset controller being defined in devicetree in
"lane" child nodes, devm_reset_control_get_exclusive() cannot be used
directly.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) -
Debian
CVE-2022-49396: linux - In the Linux kernel, the following vulnerability has been resolved: phy: qcom-q...
vendor_debian·2022·CVSS 5.5
CVE-2022-49396 [MEDIUM] CVE-2022-49396: linux - In the Linux kernel, the following vulnerability has been resolved: phy: qcom-q...
In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp: fix reset-controller leak on probe errors Make sure to release the lane reset controller in case of a late probe error (e.g. probe deferral). Note that due to the reset controller being defined in devicetree in "lane" child nodes, devm_reset_control_get_exclusive() cannot be used directly.
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved (fixed in 5.10.127-1)
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: resolved (fixed in 5.18.5-1)
GHSA
GHSA-6j7p-4wh4-pf8x: In the Linux kernel, the following vulnerability has been resolved:
phy: qcom-qmp: fix reset-controller leak on probe errors
Make sure to release th
ghsa_unreviewed·2025-09-22
CVE-2022-49396 [MEDIUM] CWE-401 GHSA-6j7p-4wh4-pf8x: In the Linux kernel, the following vulnerability has been resolved:
phy: qcom-qmp: fix reset-controller leak on probe errors
Make sure to release th
In the Linux kernel, the following vulnerability has been resolved:
phy: qcom-qmp: fix reset-controller leak on probe errors
Make sure to release the lane reset controller in case of a late probe
error (e.g. probe deferral).
Note that due to the reset controller being defined in devicetree in
"lane" child nodes, devm_reset_control_get_exclusive() cannot be used
directly.
OSV
CVE-2022-49396: In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp: fix reset-controller leak on probe errors Make sure to release the
osv·2025-02-26·CVSS 5.5
CVE-2022-49396 [MEDIUM] CVE-2022-49396: In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp: fix reset-controller leak on probe errors Make sure to release the
In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp: fix reset-controller leak on probe errors Make sure to release the lane reset controller in case of a late probe error (e.g. probe deferral). Note that due to the reset controller being defined in devicetree in "lane" child nodes, devm_reset_control_get_exclusive() cannot be used directly.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2156dc390402043ba5982489c6625adcb0b0975chttps://git.kernel.org/stable/c/4d2900f20edfe541f75756a00deeb2ffe7c66bc1https://git.kernel.org/stable/c/7ac21b24af859c097eb4034e93430056068f8f31https://git.kernel.org/stable/c/8c03eb0c8982677b4e17174073a011788891304dhttps://git.kernel.org/stable/c/a39d9eccb333b8c07c43ebea1c6dfda122378a0fhttps://git.kernel.org/stable/c/b7b5fbcaac5355e2e695dc0c08a0fcf248250388https://git.kernel.org/stable/c/ba173a6f8d8dffed64bb13ab23081bdddfb464f0https://git.kernel.org/stable/c/feb05b10b3ed3ae21b851520a0d0b71685439517
2025-02-26
Published