CVE-2022-50139
published 2025-06-18CVE-2022-50139: In the Linux kernel, the following vulnerability has been resolved: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc() We should call…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()
We should call of_node_put() for the reference returned by
of_get_child_by_name() which has increased the refcount.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 30d2617fd7ed052c30d1c21ddd4af4703d922be8 < e6db5780c2bf6e23be7b315809ef349b4b4f2213 | e6db5780c2bf6e23be7b315809ef349b4b4f2213 |
| linux | linux | >= 30d2617fd7ed052c30d1c21ddd4af4703d922be8 < 4070f3c83cd28267f469a59751480ad39435f26a | 4070f3c83cd28267f469a59751480ad39435f26a |
| linux | linux | >= 30d2617fd7ed052c30d1c21ddd4af4703d922be8 < 0e0a40c803643f4edc30f0660f2f3bea4d57a99a | 0e0a40c803643f4edc30f0660f2f3bea4d57a99a |
| linux | linux | >= 30d2617fd7ed052c30d1c21ddd4af4703d922be8 < 3503305225ca24c3229414c769323fb8bf39b4bf | 3503305225ca24c3229414c769323fb8bf39b4bf |
| linux | linux | >= 30d2617fd7ed052c30d1c21ddd4af4703d922be8 < 220fafb4ed04187e9c17be4152da5a7f2ffbdd8c | 220fafb4ed04187e9c17be4152da5a7f2ffbdd8c |
| linux | linux_kernel | >= 0 < 5.10.140-1 | 5.10.140-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 5.11 < 5.15.61 | 5.15.61 |
| linux | linux_kernel | >= 5.16 < 5.18.18 | 5.18.18 |
| linux | linux_kernel | >= 5.19 < 5.19.2 | 5.19.2 |
| linux | linux_kernel | >= 5.8 < 5.10.137 | 5.10.137 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()
vendor_redhat·2025-06-18·CVSS 5.5
CVE-2022-50139 [MEDIUM] CWE-911 kernel: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()
kernel: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()
In the Linux kernel, the following vulnerability has been resolved:
usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()
We should call of_node_put() for the reference returned by
of_get_child_by_name() which has increased the refcount.
A flaw was found in the aspeed-vhub module in the Linux kernel. A missing decrement of the reference count will cause a memory leak, potentially impacting system performance and resulting in a denial of service.
Statement: This issue has been fixed in Red Hat Enterprise Linux 9.2 via RHSA-2023:2458 [1].
[1]. https://access.redhat.com/errata/RHSA-2023:2458
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affec
Debian
CVE-2022-50139: linux - In the Linux kernel, the following vulnerability has been resolved: usb: aspeed...
vendor_debian·2022·CVSS 5.5
CVE-2022-50139 [MEDIUM] CVE-2022-50139: linux - In the Linux kernel, the following vulnerability has been resolved: usb: aspeed...
In the Linux kernel, the following vulnerability has been resolved: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc() We should call of_node_put() for the reference returned by of_get_child_by_name() which has increased the refcount.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.140-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
GHSA
GHSA-q93g-68ww-g9xv: In the Linux kernel, the following vulnerability has been resolved:
usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()
We should call o
ghsa_unreviewed·2025-06-18
CVE-2022-50139 [MEDIUM] GHSA-q93g-68ww-g9xv: In the Linux kernel, the following vulnerability has been resolved:
usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()
We should call o
In the Linux kernel, the following vulnerability has been resolved:
usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()
We should call of_node_put() for the reference returned by
of_get_child_by_name() which has increased the refcount.
OSV
CVE-2022-50139: In the Linux kernel, the following vulnerability has been resolved: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc() We should call of_
osv·2025-06-18·CVSS 5.5
CVE-2022-50139 [MEDIUM] CVE-2022-50139: In the Linux kernel, the following vulnerability has been resolved: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc() We should call of_
In the Linux kernel, the following vulnerability has been resolved: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc() We should call of_node_put() for the reference returned by of_get_child_by_name() which has increased the refcount.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0e0a40c803643f4edc30f0660f2f3bea4d57a99ahttps://git.kernel.org/stable/c/220fafb4ed04187e9c17be4152da5a7f2ffbdd8chttps://git.kernel.org/stable/c/3503305225ca24c3229414c769323fb8bf39b4bfhttps://git.kernel.org/stable/c/4070f3c83cd28267f469a59751480ad39435f26ahttps://git.kernel.org/stable/c/e6db5780c2bf6e23be7b315809ef349b4b4f2213
2025-06-18
Published