CVE-2022-50703

UnknownEPSS 0.20%

Last modified

CVE-2022-50703 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: soc: qcom: smsm: Fix refcount leak bugs in qcom_smsm_probe() There are two refcount leak bugs in qcom_smsm_probe(): (1) The 'local_node' is escaped out from for_each_child_of_node() as the break of iteration, we should call of_node_put() for it in error path or when it is not used anymore. (2) The 'node' is escaped out from for_each_available_child_of_node() as the 'goto', we should call of_node_put() for it in goto target.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: smsm: Fix refcount leak bugs in qcom_smsm_probe() There are two refcount leak bugs in qcom_smsm_probe(): (1) The 'local_node' is escaped out from for_each_child_of_node() as the break of iteration, we should call of_node_put() for it in error path or when it is not used anymore. (2) The 'node' is escaped out from for_each_available_child_of_node() as the 'goto', we should call of_node_put() for it in goto target.

Metrics

EPSS Probability
0.20%

9.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= c97c4090ff72297a878a37715bd301624b71c885, < 1bbe75d466e5118b7d49ef4a346c3ce5742da4e8; >= c97c4090ff72297a878a37715bd301624b71c885, < bd4666bf5562fe8e8e5e9bd6fc805d30e1767f43; >= c97c4090ff72297a878a37715bd301624b71c885, < 42df28994eba7b56c762f7bbe7efd5611a1cd15b; >= c97c4090ff72297a878a37715bd301624b71c885, < 1e3ed59370c712df436791efed120f0c082aa9bc; >= c97c4090ff72297a878a37715bd301624b71c885, < 39781c98ad46b4e85053345dff797240c1ed7935; >= c97c4090ff72297a878a37715bd301624b71c885, < 96e0028debdd07a6d582f0dfadf9a3ec2b5fffff; >= c97c4090ff72297a878a37715bd301624b71c885, < 8fb6112bd49c0e49f2cf51604231d85ff00284bb; >= c97c4090ff72297a878a37715bd301624b71c885, < ee7fc83ce0e6986ff9b1c1d7e994fbbf8d43861d; >= c97c4090ff72297a878a37715bd301624b71c885, < af8f6f39b8afd772fda4f8e61823ef8c021bf382
LinuxLinux4.5

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50703?
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: smsm: Fix refcount leak bugs in qcom_smsm_probe() There are two refcount leak bugs in qcom_smsm_probe(): (1) The 'local_node' is escaped out from for_each_child_of_node() as the break of iteration, we should call of_node_put() for it in error path or when it is not used anymore. (2) The 'node' is escaped out from for_each_available_child_of_node() as the 'goto', we should call of_node_put() for it in goto target.
How severe is CVE-2022-50703?
Severity scoring for CVE-2022-50703 is pending analysis. The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50703?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50703?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST