cbcvebase.
CVE-2022-50108
published 2025-06-18

CVE-2022-50108: In the Linux kernel, the following vulnerability has been resolved: mfd: max77620: Fix refcount leak in max77620_initialise_fps of_get_child_by_name() returns…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved: mfd: max77620: Fix refcount leak in max77620_initialise_fps of_get_child_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 327156c593600e0f08575621c2a56f311d482e7a < b948ff8a9e9ad46d4dff9127777caa14c8c2b53cb948ff8a9e9ad46d4dff9127777caa14c8c2b53c
linuxlinux>= 327156c593600e0f08575621c2a56f311d482e7a < afdbadbf18c19779d7bc5df70d872924f9bbd76bafdbadbf18c19779d7bc5df70d872924f9bbd76b
linuxlinux>= 327156c593600e0f08575621c2a56f311d482e7a < facd31bbc799f4d0cd25d9d688af7ca41e7f38eefacd31bbc799f4d0cd25d9d688af7ca41e7f38ee
linuxlinux>= 327156c593600e0f08575621c2a56f311d482e7a < 50d5fe8cb94c319cb4316f4d824570c07556535450d5fe8cb94c319cb4316f4d824570c075565354
linuxlinux>= 327156c593600e0f08575621c2a56f311d482e7a < a29c40814039535b950149311986a5f348b5db14a29c40814039535b950149311986a5f348b5db14
linuxlinux>= 327156c593600e0f08575621c2a56f311d482e7a < 1520669c8255bd637c6b248b2be910e2688d38dd1520669c8255bd637c6b248b2be910e2688d38dd
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.7 < 5.4.2115.4.211
linuxlinux_kernel>= 5.11 < 5.15.615.15.61
linuxlinux_kernel>= 5.16 < 5.18.185.18.18
linuxlinux_kernel>= 5.19 < 5.19.25.19.2
linuxlinux_kernel>= 5.5 < 5.10.1375.10.137

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.