CVE-2022-50777 — Missing Release of Resource after Effective Lifetime in Linux
Severity
4.0MEDIUM
No vectorEPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Description
In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_device() return device node with refcount incremented.
Call put_device() to relese it when not needed anymore.
Affected Packages4 packages
▶CVEListV5linux/linux3f7056e1822d648f8022997497edc6cad2ad1e73 — 53526dbc8aa6b95e9fc2ab1e29b1a9145721da24+10
🔴Vulnerability Details
3GHSA▶
GHSA-2jvw-hf8m-phpv: In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_devi↗2025-12-24
OSV▶
CVE-2022-50777: In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device↗2025-12-24