CVE-2022-50718Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 92.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix pci device refcount leak As comment of pci_get_domain_bus_and_slot() says, it returns a pci device with refcount increment, when finish using it, the caller must decrement the reference count by calling pci_dev_put(). So before returning from amdgpu_device_resume|suspend_display_audio(), pci_dev_put() is called to avoid refcount leak.

Affected Packages4 packages

Linuxlinux/linux_kernel5.8.05.10.163+3
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux3f12acc8d6d4b2e62fab8f652d7075a859d80b423725a8f26bdbc38dfdf545836117f1e069277c91+5
debiandebian/linux< linux 6.1.4-1 (bookworm)

🔴Vulnerability Details

3
OSV
drm/amdgpu: fix pci device refcount leak2025-12-24
GHSA
GHSA-7848-864h-rr9q: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix pci device refcount leak As comment of pci_get_domain_bus_and_sl2025-12-24
OSV
CVE-2022-50718: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix pci device refcount leak As comment of pci_get_domain_bus_and_slot2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Denial of Service due to PCI device reference count leak2025-12-24
Debian
CVE-2022-50718: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50718 Impact, Exploitability, and Mitigation Steps | Wiz