cbcvebase.
CVE-2022-50246
published 2025-09-15

CVE-2022-50246: In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci: fix of node refcount leak in tcpci_register_port() I got the following…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci: fix of node refcount leak in tcpci_register_port() I got the following report while doing device(mt6370-tcpc) load test with CONFIG_OF_UNITTEST and CONFIG_OF_DYNAMIC enabled: OF: ERROR: memory leak, expected refcount 1 instead of 2, of_node_get()/of_node_put() unbalanced - destroy cset entry: attach overlay node /i2c/pmic@34/tcpc/connector The 'fwnode' set in tcpci_parse_config() which is called in tcpci_register_port(), its node refcount is increased in device_get_named_child_node(). It needs be put while exiting, so call fwnode_handle_put() in the error path of tcpci_register_port() and in tcpci_unregister_port() to avoid leak.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 5e85a04c8c0d271d7561a770b85741f186398868 < 4f257e2eba419ab4cd880c822346450e4e7b2af34f257e2eba419ab4cd880c822346450e4e7b2af3
linuxlinux>= 5e85a04c8c0d271d7561a770b85741f186398868 < d3b6c28a71f111a6c67ddc3238aab95910fd86cfd3b6c28a71f111a6c67ddc3238aab95910fd86cf
linuxlinux>= 5e85a04c8c0d271d7561a770b85741f186398868 < ba75be6f0d9d028d20852564206565a4c03e3288ba75be6f0d9d028d20852564206565a4c03e3288
linuxlinux>= 5e85a04c8c0d271d7561a770b85741f186398868 < e75a324409715bd71348f79a49aa61b69dbeb676e75a324409715bd71348f79a49aa61b69dbeb676
linuxlinux>= 5e85a04c8c0d271d7561a770b85741f186398868 < 5f125507d2270035dfcf83fbff6cff5a143e200c5f125507d2270035dfcf83fbff6cff5a143e200c
linuxlinux>= 5e85a04c8c0d271d7561a770b85741f186398868 < 0384e87e3fec735e47f1c133c796f32ef7a72a9b0384e87e3fec735e47f1c133c796f32ef7a72a9b
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.19 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.