CVE-2023-22996Missing Release of Resource after Effective Lifetime in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 81.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28

Description

In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference after use, e.g., with put_device.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ph68-qqgf-rq69: In the Linux kernel before 52023-02-28
OSV
CVE-2023-22996: In the Linux kernel before 52023-02-28

📋Vendor Advisories

3
Red Hat
kernel: soc: qcom: aoss: missing put_device call in qmp_get()2023-02-28
Microsoft
In the Linux kernel before 5.17.2 drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference after use e.g. with put_device.2023-02-14
Debian
CVE-2023-22996: linux - In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release...2023