cbcvebase.
CVE-2022-50572
published 2025-10-22

CVE-2022-50572: In the Linux kernel, the following vulnerability has been resolved: ASoC: audio-graph-card: fix refcount leak of cpu_ep in __graph_for_each_link() The…

PriorityP418
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: audio-graph-card: fix refcount leak of cpu_ep in __graph_for_each_link() The of_get_next_child() returns a node with refcount incremented, and decrements the refcount of prev. So in the error path of the while loop, of_node_put() needs be called for cpu_ep.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= fce9b90c1ab7e915553c57353355700c79b39c86 < ed1376f771404917c2ec3ebc617431ec01146134ed1376f771404917c2ec3ebc617431ec01146134
linuxlinux>= fce9b90c1ab7e915553c57353355700c79b39c86 < 06c9d468c06806dab752eb8e72addbf3792c102306c9d468c06806dab752eb8e72addbf3792c1023
linuxlinux>= fce9b90c1ab7e915553c57353355700c79b39c86 < 85eb5c952b7fe2d2059beaa4a4dd26688b25547b85eb5c952b7fe2d2059beaa4a4dd26688b25547b
linuxlinux>= fce9b90c1ab7e915553c57353355700c79b39c86 < 49dad92af6892f46851af989ef3aa7cd7316c38949dad92af6892f46851af989ef3aa7cd7316c389
linuxlinux>= fce9b90c1ab7e915553c57353355700c79b39c86 < 4cc8431ec77a43ea106d8bde0860c61cfdda1cd04cc8431ec77a43ea106d8bde0860c61cfdda1cd0
linuxlinux>= fce9b90c1ab7e915553c57353355700c79b39c86 < 8ab2d12c726f0fde0692fa5d81d8019b3dcd62d08ab2d12c726f0fde0692fa5d81d8019b3dcd62d0
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.1.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.