CVE-2022-49389

MEDIUM EPSS 19.3%
Published Feb 26, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Feb 26, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: usb: usbip: fix a refcount leak in stub_probe() usb_get_dev() is called in stub_device_alloc(). When stub_probe() fails after that, usb_put_dev() needs to be called to release the reference. Fix this by moving usb_put_dev() to sdev_free error path handling. Find this by code review.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
19.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥3.16.58  –  <3.17
linuxlinux_kernel*≥3.18.110  –  <4.9.318
linuxlinux_kernel*≥4.10  –  <4.14.283
linuxlinux_kernel*≥4.15  –  <4.19.247
linuxlinux_kernel*≥4.20  –  <5.4.198
linuxlinux_kernel*≥5.5  –  <5.10.122
linuxlinux_kernel*≥5.11  –  <5.15.47
linuxlinux_kernel*≥5.16  –  <5.17.15
linuxlinux_kernel*≥5.18  –  <5.18.4

References 9

  • git.kernel.org https://git.kernel.org/stable/c/11c65408bd0ba1d9cd1307caa38169292de9cdfb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/247d3809e45a34d9e1a3a2bb7012e31ed8b46031
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2f0ae93ec33c8456cdfbf7876b80403a6318ebce
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/51422046be504515eb5a591adf0f424b62f46804
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6bafee2f18af5e5ac125e42960bc65496d0e56a0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8afb048800919d0ab10c57983940eba956339f21
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9ec4cbf1cc55d126759051acfe328d489c5d6e60
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bcbb795a9e78180d74c6ab21518da87e803dfdce
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f20d2d3b3364ce6525c050a8b6b4c54c8c19674d
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/11c65408bd0ba1d9cd1307caa38169292de9cdfb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/247d3809e45a34d9e1a3a2bb7012e31ed8b46031
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2f0ae93ec33c8456cdfbf7876b80403a6318ebce
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/51422046be504515eb5a591adf0f424b62f46804
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6bafee2f18af5e5ac125e42960bc65496d0e56a0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8afb048800919d0ab10c57983940eba956339f21
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9ec4cbf1cc55d126759051acfe328d489c5d6e60
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bcbb795a9e78180d74c6ab21518da87e803dfdce
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f20d2d3b3364ce6525c050a8b6b4c54c8c19674d
    Patch