CVE-2022-48961

Source
https://cve.org/CVERecord?id=CVE-2022-48961
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48961.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-48961
Downstream
Related
Published
2024-10-21T20:05:45Z
Modified
2026-08-12T03:51:20Z
Summary
net: mdio: fix unbalanced fwnode reference count in mdio_device_release()
Details

In the Linux kernel, the following vulnerability has been resolved:

net: mdio: fix unbalanced fwnode reference count in mdio_device_release()

There is warning report about of_node refcount leak while probing mdio device:

OF: ERROR: memory leak, expected refcount 1 instead of 2, of_node_get()/of_node_put() unbalanced - destroy cset entry: attach overlay node /spi/soc@0/mdio@710700c0/ethernet@4

In of_mdiobus_register_device(), we increase fwnode refcount by fwnode_handle_get() before associating the of_node with mdio device, but it has never been decreased in normal path. Since that, in mdio_device_release(), it needs to call fwnode_handle_put() in addition instead of calling kfree() directly.

After above, just calling mdio_device_free() in the error handle path of of_mdiobus_register_device() is enough to keep the refcount balanced.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48961.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a9049e0c513c4521dbfaa302af8ed08b3366b41f
Fixed
16854177745a5648f8ec322353b432e18460f43a
Fixed
a5c6de1a6656b8cc6bce7cb3d9874dd7df4968c3
Fixed
cb37617687f2bfa5b675df7779f869147c9002bd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48961.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
5.15.83
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.13

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48961.json"