PT-2025-26039 · Linux+1 · Linux Kernel+1

Published

2022-07-13

·

Updated

2025-11-18

·

CVE-2022-50113

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A refcount leak bug was found in the graph get type() function of the Linux kernel's ASoc audio-graph-card2 component. The issue arises because of node put() is not called for the reference before its replacement, which was returned by of get parent() and had its refcount increased. Additionally, of node put() should be called before returning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2026-02812
CVE-2022-50113
RHSA-2023:2458
RHSA-2023:2951

Affected Products

Astra Linux
Linux Kernel