CVE-2022-50777

UnknownEPSS 0.22%

Last modified

CVE-2022-50777 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.

Metrics

EPSS Probability
0.22%

12.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 3f7056e1822d648f8022997497edc6cad2ad1e73, < 53526dbc8aa6b95e9fc2ab1e29b1a9145721da24; >= ab4e6ee578e88a659938db8fbf33720bc048d29c, < 78b0b1ff525d9be4babf5a148a4de0d50042d95d; >= ab4e6ee578e88a659938db8fbf33720bc048d29c, < 00616bd1913a4f879679e02dc08c2f501ca2bd4c; >= ab4e6ee578e88a659938db8fbf33720bc048d29c, < 106d0d33c9d1ec4ddeeffc1fdc717ff09953d4ed; >= ab4e6ee578e88a659938db8fbf33720bc048d29c, < 4d112f001612c79927c1ecf29522b34c4fa292e0; >= ab4e6ee578e88a659938db8fbf33720bc048d29c, < 52841e71253e6ace72751c72560950474a57d04c; >= ab4e6ee578e88a659938db8fbf33720bc048d29c, < ee84d37a5f08ed1121cdd16f8f3ed87552087a21; >= ab4e6ee578e88a659938db8fbf33720bc048d29c, < d039535850ee47079d59527e96be18d8e0daa84b; a5a849c9e8a6c357f84a5e249cb468f20da6d28f; 900812a0d318954400d20b0190c7d788b4ff2cc2; >= 4.14.74, < 4.14.303; >= 4.9.131, < 4.10; >= 4.18.12, < 4.19
LinuxLinux4.19

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50777?
In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.
How severe is CVE-2022-50777?
Severity scoring for CVE-2022-50777 is pending analysis. The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50777?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50777?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST