cbcvebase.
CVE-2022-50480
published 2025-10-04

CVE-2022-50480: In the Linux kernel, the following vulnerability has been resolved: memory: pl353-smc: Fix refcount leak bug in pl353_smc_probe() The break of…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: memory: pl353-smc: Fix refcount leak bug in pl353_smc_probe() The break of for_each_available_child_of_node() needs a corresponding of_node_put() when the reference 'child' is not used anymore. Here we do not need to call of_node_put() in fail path as '!match' means no break. While the of_platform_device_create() will created a new reference by 'child' but it has considered the refcounting.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= fee10bd2267868f2a3e7ba008ef7665aac5e4412 < b37f4a711e5d4bf3608ccbc6de82b52e92b441a0b37f4a711e5d4bf3608ccbc6de82b52e92b441a0
linuxlinux>= fee10bd2267868f2a3e7ba008ef7665aac5e4412 < fde46754d5483bc398018bbec3c8ef5c55219e67fde46754d5483bc398018bbec3c8ef5c55219e67
linuxlinux>= fee10bd2267868f2a3e7ba008ef7665aac5e4412 < 566b143aa5112a0c2784e20603778518bb799537566b143aa5112a0c2784e20603778518bb799537
linuxlinux>= fee10bd2267868f2a3e7ba008ef7665aac5e4412 < 44db35ceb94756ba513dcf6b69bf9e949b28469c44db35ceb94756ba513dcf6b69bf9e949b28469c
linuxlinux>= fee10bd2267868f2a3e7ba008ef7665aac5e4412 < 49605dc25e7fb33bf8b671279d4468531da90f8949605dc25e7fb33bf8b671279d4468531da90f89
linuxlinux>= fee10bd2267868f2a3e7ba008ef7665aac5e4412 < 61b3c876c1cbdb1efd1f52a1f348580e6e14efb661b3c876c1cbdb1efd1f52a1f348580e6e14efb6
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 5.0 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.