cbcvebase.
CVE-2022-49714
published 2025-02-26

CVE-2022-49714: In the Linux kernel, the following vulnerability has been resolved: irqchip/realtek-rtl: Fix refcount leak in map_interrupts of_find_node_by_phandle() returns…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.8th percentile
In the Linux kernel, the following vulnerability has been resolved: irqchip/realtek-rtl: Fix refcount leak in map_interrupts of_find_node_by_phandle() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. This function doesn't call of_node_put() in error path. Call of_node_put() directly after of_property_read_u32() to cover both normal path and error path.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 9f3a0f34b84ad1b9a8f2bdae44b66f16685b2143 < e85b1b797de0e7a271b906291ce28245822820b8e85b1b797de0e7a271b906291ce28245822820b8
linuxlinux>= 9f3a0f34b84ad1b9a8f2bdae44b66f16685b2143 < f6d6223df0666fbc054e3a8c6ac14eb0af37c286f6d6223df0666fbc054e3a8c6ac14eb0af37c286
linuxlinux>= 9f3a0f34b84ad1b9a8f2bdae44b66f16685b2143 < eff4780f83d0ae3e5b6c02ff5d999dc4c1c5c8ceeff4780f83d0ae3e5b6c02ff5d999dc4c1c5c8ce
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.12 < 5.15.495.15.49
linuxlinux_kernel>= 5.16 < 5.18.65.18.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.