cbcvebase.
CVE-2022-50249
published 2025-09-15

CVE-2022-50249: In the Linux kernel, the following vulnerability has been resolved: memory: of: Fix refcount leak bug in of_get_ddr_timings() We should add the of_node_put()…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved: memory: of: Fix refcount leak bug in of_get_ddr_timings() We should add the of_node_put() when breaking out of for_each_child_of_node() as it will automatically increase and decrease the refcount.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < a4d0bd4388e1a39df47e8aaa044ef6a7ee626e48a4d0bd4388e1a39df47e8aaa044ef6a7ee626e48
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < a4f7eb83852a65b6f8dea7dcc42b7c76d4d9b0a3a4f7eb83852a65b6f8dea7dcc42b7c76d4d9b0a3
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < 68c9c4e6495b825be3a8946df1a0148399555fe468c9c4e6495b825be3a8946df1a0148399555fe4
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < 85a40bfb8e7a170abcf9dae2c0898a1983e48daa85a40bfb8e7a170abcf9dae2c0898a1983e48daa
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < daaec4b3fe2297b022c6b2d6bf48b6e5265a60b9daaec4b3fe2297b022c6b2d6bf48b6e5265a60b9
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < 2680690f9ce4e6abbb4f559e97271c15b7eeda972680690f9ce4e6abbb4f559e97271c15b7eeda97
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < 62ccab6e3376f8a22167c3b81468ae4f3e7d25f162ccab6e3376f8a22167c3b81468ae4f3e7d25f1
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < 1c6cac6fa4d08aea161f83d38117d733b3c3a0001c6cac6fa4d08aea161f83d38117d733b3c3a000
linuxlinux>= e6b42eb6a66c188642aeb447312938c6f6ebee86 < 05215fb32010d4afb68fbdbb4d237df6e2d4567b05215fb32010d4afb68fbdbb4d237df6e2d4567b
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 3.7 < 4.9.3314.9.331
linuxlinux_kernel>= 4.10 < 4.14.2964.14.296
linuxlinux_kernel>= 4.15 < 4.19.2624.19.262
linuxlinux_kernel>= 4.20 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.