CVE-2022-48856

In the Linux kernel, the following vulnerability has been resolved: gianfar: ethtool: Fix refcount leak in gfar_get_ts_info The of_find_compatible_node() function returns a node pointer with refcount incremented, We should use of_node_put() on it when done Add the missing of_node_put() to release the refcount.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Jul 2024, 15:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: gianfar: ethtool: corrige la fuga de refcount en gfar_get_ts_info La función of_find_compatible_node() devuelve un puntero de nodo con refcount incrementado. Deberíamos usar of_node_put() en ella cuando haya terminado. Agregue el of_node_put() que falta para liberar el recuento.
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/0e1b9a2078e07fb1e6e91bf8badfd89ecab1e848 - () https://git.kernel.org/stable/c/0e1b9a2078e07fb1e6e91bf8badfd89ecab1e848 - Patch
References () https://git.kernel.org/stable/c/21044e679ed535345042d2023f7df0ca8e897e2a - () https://git.kernel.org/stable/c/21044e679ed535345042d2023f7df0ca8e897e2a - Patch
References () https://git.kernel.org/stable/c/2ac5b58e645c66932438bb021cb5b52097ce70b0 - () https://git.kernel.org/stable/c/2ac5b58e645c66932438bb021cb5b52097ce70b0 - Patch
References () https://git.kernel.org/stable/c/6263f2eb93a85ad7df504daf0c341a7fb6bbe8a6 - () https://git.kernel.org/stable/c/6263f2eb93a85ad7df504daf0c341a7fb6bbe8a6 - Patch
References () https://git.kernel.org/stable/c/f49f646f9ec296fc0afe7ae92c2bb47f23e3846c - () https://git.kernel.org/stable/c/f49f646f9ec296fc0afe7ae92c2bb47f23e3846c - Patch
References () https://git.kernel.org/stable/c/f7b3b520349193f8a82cca74daf366199e06add9 - () https://git.kernel.org/stable/c/f7b3b520349193f8a82cca74daf366199e06add9 - Patch
CWE CWE-401
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

16 Jul 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-16 13:15

Updated : 2024-07-23 15:11


NVD link : CVE-2022-48856

Mitre link : CVE-2022-48856

CVE.ORG link : CVE-2022-48856


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime