CVE-2022-48896

medium

Description

In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix pci device refcount leak As the comment of pci_get_domain_bus_and_slot() says, it returns a PCI device with refcount incremented, when finish using it, the caller must decrement the reference count by calling pci_dev_put(). In ixgbe_get_first_secondary_devfn() and ixgbe_x550em_a_has_mii(), pci_dev_put() is called to avoid leak.

References

https://git.kernel.org/stable/c/c49996c6aa03590e4ef5add8772cb6068d99fd59

https://git.kernel.org/stable/c/b93fb4405fcb5112c5739c5349afb52ec7f15c07

https://git.kernel.org/stable/c/53cefa802f070d46c0c518f4865be2c749818a18

https://git.kernel.org/stable/c/4c93422a54cd6a349988f42e1c6bf082cf4ea9d8

https://git.kernel.org/stable/c/112df4cd2b09acd64bcd18f5ef83ba5d07b34bf0

Details

Source: Mitre, NVD

Published: 2024-08-21

Updated: 2024-09-11

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium