cbcvebase.
CVE-2022-49712
published 2025-02-26

CVE-2022-49712: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: lpc32xx_udc: Fix refcount leak in lpc32xx_udc_probe of_parse_phandle() returns…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.8th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: lpc32xx_udc: Fix refcount leak in lpc32xx_udc_probe of_parse_phandle() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak. of_node_put() will check NULL pointer.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 24a28e4283510dcd58890379a42b8a7d3201d9d3 < d85e4e6284a91aa2d1ab004e9d84b9c09b4aa203d85e4e6284a91aa2d1ab004e9d84b9c09b4aa203
linuxlinux>= 24a28e4283510dcd58890379a42b8a7d3201d9d3 < 0ef6917c0524da5b88496b9706628ffef108b9bb0ef6917c0524da5b88496b9706628ffef108b9bb
linuxlinux>= 24a28e4283510dcd58890379a42b8a7d3201d9d3 < 2a598da14856ead80c726b38ba426c68637d92112a598da14856ead80c726b38ba426c68637d9211
linuxlinux>= 24a28e4283510dcd58890379a42b8a7d3201d9d3 < b75bddfcc18170ce8e3fb695a76ec2dec4ce0ea5b75bddfcc18170ce8e3fb695a76ec2dec4ce0ea5
linuxlinux>= 24a28e4283510dcd58890379a42b8a7d3201d9d3 < 57901c658f77d9ea2e772f35cb38e47efb54c55857901c658f77d9ea2e772f35cb38e47efb54c558
linuxlinux>= 24a28e4283510dcd58890379a42b8a7d3201d9d3 < 46da1e4a8b6329479433b2a4056941dfdd7f3efd46da1e4a8b6329479433b2a4056941dfdd7f3efd
linuxlinux>= 24a28e4283510dcd58890379a42b8a7d3201d9d3 < 727c82d003e0ec64411fd1257a9a57de4ad7a99a727c82d003e0ec64411fd1257a9a57de4ad7a99a
linuxlinux>= 24a28e4283510dcd58890379a42b8a7d3201d9d3 < 4757c9ade34178b351580133771f510b5ffcf9c84757c9ade34178b351580133771f510b5ffcf9c8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 3.5 < 4.9.3204.9.320
linuxlinux_kernel>= 4.10 < 4.14.2854.14.285
linuxlinux_kernel>= 4.15 < 4.19.2494.19.249
linuxlinux_kernel>= 4.20 < 5.4.2005.4.200
linuxlinux_kernel>= 5.11 < 5.15.495.15.49
linuxlinux_kernel>= 5.16 < 5.18.65.18.6
linuxlinux_kernel>= 5.5 < 5.10.1245.10.124

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.