cbcvebase.
CVE-2022-50157
published 2025-06-18

CVE-2022-50157: In the Linux kernel, the following vulnerability has been resolved: PCI: microchip: Fix refcount leak in mc_pcie_init_irq_domains() of_get_next_child() returns…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.5th percentile
In the Linux kernel, the following vulnerability has been resolved: PCI: microchip: Fix refcount leak in mc_pcie_init_irq_domains() of_get_next_child() returns a node pointer with refcount incremented, so we should use of_node_put() on it when we don't need it anymore. mc_pcie_init_irq_domains() only calls of_node_put() in the normal path, missing it in some error paths. Add missing of_node_put() to avoid refcount leak.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 6f15a9c9f94133bee0d861a4bf25e10aaa95219d < c0ad5c7e68d10f6f8ffb0f4329e3c19404fbca58c0ad5c7e68d10f6f8ffb0f4329e3c19404fbca58
linuxlinux>= 6f15a9c9f94133bee0d861a4bf25e10aaa95219d < 6cd5f93b5c6a66c68a91dbc604a78207252ecd436cd5f93b5c6a66c68a91dbc604a78207252ecd43
linuxlinux>= 6f15a9c9f94133bee0d861a4bf25e10aaa95219d < 880ece912b958a0c92cc0baa8e906fb9b49a4b53880ece912b958a0c92cc0baa8e906fb9b49a4b53
linuxlinux>= 6f15a9c9f94133bee0d861a4bf25e10aaa95219d < f030304fdeb87ec8f1b518c73703214aec6cc24af030304fdeb87ec8f1b518c73703214aec6cc24a
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 5.12 < 5.15.615.15.61
linuxlinux_kernel>= 5.16 < 5.18.185.18.18
linuxlinux_kernel>= 5.19 < 5.19.25.19.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.