CVE-2022-49346

Source
https://cve.org/CVERecord?id=CVE-2022-49346
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49346.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49346
Downstream
Related
Published
2025-02-26T02:11:01.485Z
Modified
2026-04-11T12:43:55.200582Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
net: dsa: lantiq_gswip: Fix refcount leak in gswip_gphy_fw_list
Details

In the Linux kernel, the following vulnerability has been resolved:

net: dsa: lantiqgswip: Fix refcount leak in gswipgphyfwlist

Every iteration of foreachavailablechildofnode() decrements the reference count of the previous node. when breaking early from a foreachavailablechildofnode() loop, we need to explicitly call ofnodeput() on the gphyfwnp. Add missing ofnodeput() to avoid refcount leak.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49346.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
14fceff4771e51b23b4485b575cf9e5b3414b89b
Fixed
7c8df6fad43d9d5d77f281f794b2a93cd02fd1a9
Fixed
c2ae49a113a5344232f1ebb93bcf18bbd11e9c39
Fixed
54d6802c4d83fa8de7696cfec06f475d5fd92d27
Fixed
32cd78c5610f02a929f63cac985e73692d05f33e
Fixed
2e007ac6fa7c9c94ad84da075c5c504afad690a0
Fixed
0737e018a05e2aa352828c52bdeed3b02cff2930

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49346.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.198
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.122
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.47
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.17.15
Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
5.18.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49346.json"