cbcvebase.
CVE-2022-49677
published 2025-02-26

CVE-2022-49677: In the Linux kernel, the following vulnerability has been resolved: ARM: cns3xxx: Fix refcount leak in cns3xxx_init of_find_compatible_node() returns a node…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ARM: cns3xxx: Fix refcount leak in cns3xxx_init of_find_compatible_node() returns a node pointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 415f59142d9d9dd023deaeb3b4dfc1aecdd3983c < b8b84e01ca94e2e1f5492353e9c24dab520b2e5bb8b84e01ca94e2e1f5492353e9c24dab520b2e5b
linuxlinux>= 415f59142d9d9dd023deaeb3b4dfc1aecdd3983c < 45bebbc8cea7d586a6216dc62814bdb380b9b29b45bebbc8cea7d586a6216dc62814bdb380b9b29b
linuxlinux>= 415f59142d9d9dd023deaeb3b4dfc1aecdd3983c < 68d4303bf59662b64bd555e2aa0518282d20aa4f68d4303bf59662b64bd555e2aa0518282d20aa4f
linuxlinux>= 415f59142d9d9dd023deaeb3b4dfc1aecdd3983c < d1359e4129ad43e43972a28838b87291c51de23dd1359e4129ad43e43972a28838b87291c51de23d
linuxlinux>= 415f59142d9d9dd023deaeb3b4dfc1aecdd3983c < c980392af1473d6d5662f70d8089c8e6d85144a4c980392af1473d6d5662f70d8089c8e6d85144a4
linuxlinux>= 415f59142d9d9dd023deaeb3b4dfc1aecdd3983c < da3ee7cd2f15922ad88a7ca6deee2eafdc7cd214da3ee7cd2f15922ad88a7ca6deee2eafdc7cd214
linuxlinux>= 415f59142d9d9dd023deaeb3b4dfc1aecdd3983c < dc5170aae24e04068fd5ea125d06c0ab51f48a27dc5170aae24e04068fd5ea125d06c0ab51f48a27
linuxlinux>= 415f59142d9d9dd023deaeb3b4dfc1aecdd3983c < 1ba904b6b16e08de5aed7c1349838d9cd0d178c51ba904b6b16e08de5aed7c1349838d9cd0d178c5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 3.10 < 4.9.3214.9.321
linuxlinux_kernel>= 4.10 < 4.14.2864.14.286
linuxlinux_kernel>= 4.15 < 4.19.2504.19.250
linuxlinux_kernel>= 4.20 < 5.4.2025.4.202
linuxlinux_kernel>= 5.11 < 5.15.515.15.51
linuxlinux_kernel>= 5.16 < 5.18.85.18.8
linuxlinux_kernel>= 5.5 < 5.10.1275.10.127

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.