cbcvebase.
CVE-2022-50868
published 2025-12-30

CVE-2022-50868: In the Linux kernel, the following vulnerability has been resolved: hwrng: amd - Fix PCI device refcount leak for_each_pci_dev() is implemented by…

PriorityP420low5.5
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: hwrng: amd - Fix PCI device refcount leak for_each_pci_dev() is implemented by pci_get_device(). The comment of pci_get_device() says that it will increase the reference count for the returned pci_dev and also decrease the reference count for the input pci_dev @from if it is not NULL. If we break for_each_pci_dev() loop with pdev not NULL, we need to call pci_dev_put() to decrease the reference count. Add the missing pci_dev_put() for the normal and error path.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < f1c97f72ffd504f49882774e2ab689d982dc7afcf1c97f72ffd504f49882774e2ab689d982dc7afc
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < 526c316948819d3ecd2bb20fe5e2580c51a1b760526c316948819d3ecd2bb20fe5e2580c51a1b760
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < e246f5eff26055bdcb61a2cc99c50af72a19680fe246f5eff26055bdcb61a2cc99c50af72a19680f
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < 1199f8e02941b326c60ab71a63002b7c80e382121199f8e02941b326c60ab71a63002b7c80e38212
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < 5998e5c30e839f73e62cb29e0d9617b0d16ccba35998e5c30e839f73e62cb29e0d9617b0d16ccba3
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < 2b79a5e560779b35e1164d57ae35c48b433730822b79a5e560779b35e1164d57ae35c48b43373082
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < cb348c7908631dd9f60083a0a1542eab055d3edfcb348c7908631dd9f60083a0a1542eab055d3edf
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < 2e10ecd012ae2b2a374b34f307e9bc1e6096c03d2e10ecd012ae2b2a374b34f307e9bc1e6096c03d
linuxlinux>= 96d63c0297ccfd6d9059c614b3f5555d9441a2b3 < ecadb5b0111ea19fc7c240bb25d424a94471eb7decadb5b0111ea19fc7c240bb25d424a94471eb7d
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 2.6.18 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10.0 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15.0 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.