cbcvebase.
CVE-2022-49525
published 2025-02-26

CVE-2022-49525: In the Linux kernel, the following vulnerability has been resolved: media: cx25821: Fix the warning when removing the module When removing the module, we will…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.0th percentile
In the Linux kernel, the following vulnerability has been resolved: media: cx25821: Fix the warning when removing the module When removing the module, we will get the following warning: [ 14.746697] remove_proc_entry: removing non-empty directory 'irq/21', leaking at least 'cx25821[1]' [ 14.747449] WARNING: CPU: 4 PID: 368 at fs/proc/generic.c:717 remove_proc_entry+0x389/0x3f0 [ 14.751611] RIP: 0010:remove_proc_entry+0x389/0x3f0 [ 14.759589] Call Trace: [ 14.759792] [ 14.759975] unregister_irq_proc+0x14c/0x170 [ 14.760340] irq_free_descs+0x94/0xe0 [ 14.760640] mp_unmap_irq+0xb6/0x100 [ 14.760937] acpi_unregister_gsi_ioapic+0x27/0x40 [ 14.761334] acpi_pci_irq_disable+0x1d3/0x320 [ 14.761688] pci_disable_device+0x1ad/0x380 [ 14.762027] ? _raw_spin_unlock_irqrestore+0x2d/0x60 [ 14.762442] ? cx25821_shutdown+0x20/0x9f0 [cx25821] [ 14.762848] cx25821_finidev+0x48/0xc0 [cx25821] [ 14.763242] pci_device_remove+0x92/0x240 Fix this by freeing the irq before call pci_disable_device().

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 4d6295b6d986476232332fffd08575b185f90d814d6295b6d986476232332fffd08575b185f90d81
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 5beb85ff7d005ddb7bf604a4f2dc76f01b84b3185beb85ff7d005ddb7bf604a4f2dc76f01b84b318
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 258639bc55a586ee6df92d89786ccf1c71546d70258639bc55a586ee6df92d89786ccf1c71546d70
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 222292930c8ecc3516e03ec1f9fa8448be7ff496222292930c8ecc3516e03ec1f9fa8448be7ff496
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 3f94169affa33c9db4a439d88f09cb2ed3a333323f94169affa33c9db4a439d88f09cb2ed3a33332
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 1f0fc1dfb5fdd456657519a97fab83691b96c6a01f0fc1dfb5fdd456657519a97fab83691b96c6a0
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 9d92291698e5cc35a2b8a1106a01ddd7d60ade2d9d92291698e5cc35a2b8a1106a01ddd7d60ade2d
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 005fd553f5f10fe8618d92f94ad10f9051eac331005fd553f5f10fe8618d92f94ad10f9051eac331
linuxlinux>= 02b20b0b4cde011f7ad6b5363fb88b93f7ad4e5b < 2203436a4d24302871617373a7eb21bc17e387622203436a4d24302871617373a7eb21bc17e38762
linuxlinux_kernel< 4.9.3184.9.318
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 4.10 < 4.14.2834.14.283
linuxlinux_kernel>= 4.15 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3
linuxlinux_kernel>= 5.5 < 5.10.1215.10.121

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.