cbcvebase.
CVE-2022-49656
published 2025-02-26

CVE-2022-49656: In the Linux kernel, the following vulnerability has been resolved: ARM: meson: Fix refcount leak in meson_smp_prepare_cpus of_find_compatible_node() returns a…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ARM: meson: Fix refcount leak in meson_smp_prepare_cpus of_find_compatible_node() returns a node pointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= d850f3e5d2966e5c9eb55f66181cee960737e04c < 2e1bcd33478ef44e63a45457055060b5fe4118ad2e1bcd33478ef44e63a45457055060b5fe4118ad
linuxlinux>= d850f3e5d2966e5c9eb55f66181cee960737e04c < 3cf8ece9113242c10f83c7675ea4f4f67959ee433cf8ece9113242c10f83c7675ea4f4f67959ee43
linuxlinux>= d850f3e5d2966e5c9eb55f66181cee960737e04c < 3d90607e7e6afa89768b0aaa915b58bd2b8492763d90607e7e6afa89768b0aaa915b58bd2b849276
linuxlinux>= d850f3e5d2966e5c9eb55f66181cee960737e04c < 7208101ded1e9dcc52c8f0f8b16474211c871c1a7208101ded1e9dcc52c8f0f8b16474211c871c1a
linuxlinux>= d850f3e5d2966e5c9eb55f66181cee960737e04c < c5fbf4f74c94fd60d5e9bf9f7f8268c3601562cac5fbf4f74c94fd60d5e9bf9f7f8268c3601562ca
linuxlinux>= d850f3e5d2966e5c9eb55f66181cee960737e04c < 34d2cd3fccced12b958b8848e3eff0ee4296764c34d2cd3fccced12b958b8848e3eff0ee4296764c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.15 < 4.19.2524.19.252
linuxlinux_kernel>= 4.20 < 5.4.2055.4.205
linuxlinux_kernel>= 5.11 < 5.15.545.15.54
linuxlinux_kernel>= 5.16 < 5.18.115.18.11
linuxlinux_kernel>= 5.5 < 5.10.1305.10.130

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.