CVE-2022-50777Missing Release of Resource after Effective Lifetime in Linux

Severity
4.0MEDIUM
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.

Affected Packages4 packages

Linuxlinux/linux_kernel4.15.04.19.270+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux3f7056e1822d648f8022997497edc6cad2ad1e7353526dbc8aa6b95e9fc2ab1e29b1a9145721da24+10
debiandebian/linux< linux 6.1.7-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-2jvw-hf8m-phpv: In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_devi2025-12-24
OSV
CVE-2022-50777: In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device2025-12-24
OSV
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: Kernel: Denial of Service due to reference count leak2025-12-24
Debian
CVE-2022-50777: linux - In the Linux kernel, the following vulnerability has been resolved: net: phy: x...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50777 Impact, Exploitability, and Mitigation Steps | Wiz