cbcvebase.
CVE-2022-49644
published 2025-02-26

CVE-2022-49644: In the Linux kernel, the following vulnerability has been resolved: drm/i915: fix a possible refcount leak in intel_dp_add_mst_connector() If…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/i915: fix a possible refcount leak in intel_dp_add_mst_connector() If drm_connector_init fails, intel_connector_free will be called to take care of proper free. So it is necessary to drop the refcount of port before intel_connector_free. (cherry picked from commit cea9ed611e85d36a05db52b6457bf584b7d969e2)

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 091a4f91942a4396c67e5747f5cb38c6396d1fc5 < 72f231b9a88abcfac9f5ddaa1a0aacb3f9f87ba572f231b9a88abcfac9f5ddaa1a0aacb3f9f87ba5
linuxlinux>= 091a4f91942a4396c67e5747f5cb38c6396d1fc5 < 592f3bad00b7e2a95a6fb7a4f9e742c061c9c3c1592f3bad00b7e2a95a6fb7a4f9e742c061c9c3c1
linuxlinux>= 091a4f91942a4396c67e5747f5cb38c6396d1fc5 < 505114dda5bbfd07f4ce9a2df5b7d8ef5f2a1218505114dda5bbfd07f4ce9a2df5b7d8ef5f2a1218
linuxlinux>= 091a4f91942a4396c67e5747f5cb38c6396d1fc5 < a91522b4279bebb098106a19b91f82b9c3213be9a91522b4279bebb098106a19b91f82b9c3213be9
linuxlinux>= 091a4f91942a4396c67e5747f5cb38c6396d1fc5 < 85144df9ff4652816448369de76897c57cbb1b9385144df9ff4652816448369de76897c57cbb1b93
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.15 < 5.4.2075.4.207
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.5 < 5.10.1325.10.132

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.