PT-2023-9338 · Linux+2 · Linux Kernel+2

Published

2023-01-12

·

Updated

2024-09-27

·

CVE-2022-48881

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a refcount leak in the amd pmc probe function of the Linux kernel. The pci get domain bus and slot() function takes a reference, which the caller should release by calling pci dev put() after use. However, the reference is not released in the error path, leading to a refcount leak. This leak may allow an attacker to disclose protected information or cause a denial of service.
Recommendations To resolve the issue, ensure that pci dev put() is called in the error path to release the reference taken by pci get domain bus and slot(). As a temporary workaround, consider restricting access to the amd pmc probe function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06645
CVE-2022-48881
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3483-1

Affected Products

Linux Kernel
Red Os
Suse