cbcvebase.
CVE-2022-49431
published 2025-02-26

CVE-2022-49431: In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Add missing of_node_put in iommu_init_early_dart The device_node pointer is…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Add missing of_node_put in iommu_init_early_dart The device_node pointer is returned by of_find_compatible_node with refcount incremented. We should use of_node_put() to avoid the refcount leak.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cb4f2dc513e99c5d0485661f114e4dda73612d10cb4f2dc513e99c5d0485661f114e4dda73612d10
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dfc308d6f29aa28463deb9a12278a85a382385cadfc308d6f29aa28463deb9a12278a85a382385ca
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < df6d8b689252c0acc0448d4ae3d33f2d6db048abdf6d8b689252c0acc0448d4ae3d33f2d6db048ab
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8657e8ea23325949091da72453ba84fb73cc2bd98657e8ea23325949091da72453ba84fb73cc2bd9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7e3f1dfb9e21733d7276bc9ccea4daada163f2ba7e3f1dfb9e21733d7276bc9ccea4daada163f2ba
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 57b742a5b8945118022973e6416b71351df512fb57b742a5b8945118022973e6416b71351df512fb
linuxlinux_kernel< 5.4.1985.4.198
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3
linuxlinux_kernel>= 5.5 < 5.10.1215.10.121

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.