cbcvebase.
CVE-2022-50309
published 2025-09-15

CVE-2022-50309: In the Linux kernel, the following vulnerability has been resolved: media: xilinx: vipp: Fix refcount leak in xvip_graph_dma_init of_get_child_by_name()…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved: media: xilinx: vipp: Fix refcount leak in xvip_graph_dma_init of_get_child_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 7b0efe7534071e0153708886355d80db69525d507b0efe7534071e0153708886355d80db69525d50
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 6e7b3b1e4e9f739800cd8010b75a9bee8d808cee6e7b3b1e4e9f739800cd8010b75a9bee8d808cee
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 3c38467c3255c428cdbd3cefaccca4662f302dc93c38467c3255c428cdbd3cefaccca4662f302dc9
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 59b315353252abe7b8fdb8651ca31b8484ce287a59b315353252abe7b8fdb8651ca31b8484ce287a
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 2630cc88327a5557aa0d9cc63be95e3c6e0a55b32630cc88327a5557aa0d9cc63be95e3c6e0a55b3
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 2ea7caa9684687cf3adc1467cf4af3653a7761922ea7caa9684687cf3adc1467cf4af3653a776192
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 22b93530bbe6af9dce8e520bb6e978d1bda39d2b22b93530bbe6af9dce8e520bb6e978d1bda39d2b
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 3336210948b22c2db43e9df2ea403d251b4d24ab3336210948b22c2db43e9df2ea403d251b4d24ab
linuxlinux>= df3305156f989339529b3d6744b898d498fb1f7b < 1c78f19c3a0ea312a8178a6bfd8934eb93e9b10a1c78f19c3a0ea312a8178a6bfd8934eb93e9b10a
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 4.1 < 4.9.3314.9.331
linuxlinux_kernel>= 4.10 < 4.14.2964.14.296
linuxlinux_kernel>= 4.15 < 4.19.2624.19.262
linuxlinux_kernel>= 4.20 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.