CVE-2022-50777
published 2025-12-24CVE-2022-50777: In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return…
PriorityP420low4
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_device() return device node with refcount incremented.
Call put_device() to relese it when not needed anymore.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.7-1 (bookworm) | linux 6.1.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 3f7056e1822d648f8022997497edc6cad2ad1e73 < 53526dbc8aa6b95e9fc2ab1e29b1a9145721da24 | 53526dbc8aa6b95e9fc2ab1e29b1a9145721da24 |
| linux | linux | >= 4.14.74 < 4.14.303 | 4.14.303 |
| linux | linux | >= 4.18.12 < 4.19 | 4.19 |
| linux | linux | >= 4.9.131 < 4.10 | 4.10 |
| linux | linux | >= ab4e6ee578e88a659938db8fbf33720bc048d29c < 78b0b1ff525d9be4babf5a148a4de0d50042d95d | 78b0b1ff525d9be4babf5a148a4de0d50042d95d |
| linux | linux | >= ab4e6ee578e88a659938db8fbf33720bc048d29c < 00616bd1913a4f879679e02dc08c2f501ca2bd4c | 00616bd1913a4f879679e02dc08c2f501ca2bd4c |
| linux | linux | >= ab4e6ee578e88a659938db8fbf33720bc048d29c < 106d0d33c9d1ec4ddeeffc1fdc717ff09953d4ed | 106d0d33c9d1ec4ddeeffc1fdc717ff09953d4ed |
| linux | linux | >= ab4e6ee578e88a659938db8fbf33720bc048d29c < 4d112f001612c79927c1ecf29522b34c4fa292e0 | 4d112f001612c79927c1ecf29522b34c4fa292e0 |
| linux | linux | >= ab4e6ee578e88a659938db8fbf33720bc048d29c < 52841e71253e6ace72751c72560950474a57d04c | 52841e71253e6ace72751c72560950474a57d04c |
| linux | linux | >= ab4e6ee578e88a659938db8fbf33720bc048d29c < ee84d37a5f08ed1121cdd16f8f3ed87552087a21 | ee84d37a5f08ed1121cdd16f8f3ed87552087a21 |
| linux | linux | >= ab4e6ee578e88a659938db8fbf33720bc048d29c < d039535850ee47079d59527e96be18d8e0daa84b | d039535850ee47079d59527e96be18d8e0daa84b |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 4.14.303 | 4.14.303 |
| linux | linux_kernel | >= 4.15.0 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.19.0 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 4.20.0 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 5.11.0 < 6.0.19 | 6.0.19 |
| linux | linux_kernel | >= 5.16.0 < 6.1.5 | 6.1.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Kernel: Denial of Service due to reference count leak
vendor_redhat·2025-12-24·CVSS 4.0
CVE-2022-50777 [LOW] CWE-772 kernel: Kernel: Denial of Service due to reference count leak
kernel: Kernel: Denial of Service due to reference count leak
In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_device() return device node with refcount incremented.
Call put_device() to relese it when not needed anymore.
A flaw was found in the Linux kernel. A local attacker with low privileges and physical access could exploit a reference count leak in the `xgmiitorgmii_probe` function. This vulnerability could lead to resource exhaustion, resulting in a Denial of Service (DoS), which means the system may become unresponsive or crash.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise
Debian
CVE-2022-50777: linux - In the Linux kernel, the following vulnerability has been resolved: net: phy: x...
vendor_debian·2022
CVE-2022-50777 CVE-2022-50777: linux - In the Linux kernel, the following vulnerability has been resolved: net: phy: x...
In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.7-1)
sid: resolved (fixed in 6.1.7-1)
trixie: resolved (fixed in 6.1.7-1)
GHSA
GHSA-2jvw-hf8m-phpv: In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_devi
ghsa_unreviewed·2025-12-24
CVE-2022-50777 GHSA-2jvw-hf8m-phpv: In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_devi
In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_device() return device node with refcount incremented.
Call put_device() to relese it when not needed anymore.
OSV
CVE-2022-50777: In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device
osv·2025-12-24
CVE-2022-50777 CVE-2022-50777: In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device
In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.
OSV
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
osv·2025-12-24
CVE-2022-50777 net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_device() return device node with refcount incremented.
Call put_device() to relese it when not needed anymore.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2022-50777 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50777 CVE-2022-50777 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50777 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_device() return device node with refcount incremented.
Call put_device() to relese it when not needed anymore.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-gkeop
kernel-default-man
Sources
NVD
Debian 11, 12, 13, 14 Has Fix Added at: Dec 26, 2025
Echo Has Fix Added at: Dec 26, 2025
Red H
Bugzilla
CVE-2022-50777 kernel: Kernel: Denial of Service due to reference count leak
bugzilla·2025-12-24
CVE-2022-50777 [LOW] CVE-2022-50777 kernel: Kernel: Denial of Service due to reference count leak
CVE-2022-50777 kernel: Kernel: Denial of Service due to reference count leak
In the Linux kernel, the following vulnerability has been resolved:
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
of_phy_find_device() return device node with refcount incremented.
Call put_device() to relese it when not needed anymore.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122400-CVE-2022-50777-d1e3@gregkh/T
https://git.kernel.org/stable/c/00616bd1913a4f879679e02dc08c2f501ca2bd4chttps://git.kernel.org/stable/c/106d0d33c9d1ec4ddeeffc1fdc717ff09953d4edhttps://git.kernel.org/stable/c/4d112f001612c79927c1ecf29522b34c4fa292e0https://git.kernel.org/stable/c/52841e71253e6ace72751c72560950474a57d04chttps://git.kernel.org/stable/c/53526dbc8aa6b95e9fc2ab1e29b1a9145721da24https://git.kernel.org/stable/c/78b0b1ff525d9be4babf5a148a4de0d50042d95dhttps://git.kernel.org/stable/c/d039535850ee47079d59527e96be18d8e0daa84bhttps://git.kernel.org/stable/c/ee84d37a5f08ed1121cdd16f8f3ed87552087a21
2025-12-24
Published