PT-2025-37639 · Linux+1 · Linux Kernel+1

Published

2022-11-23

·

Updated

2025-09-15

·

CVE-2022-50337

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The get function 0() function in the Linux kernel contains a potential PCI device reference count leak. The function calls pci get domain bus and slot(), which increments the reference count of the PCI device. However, the reference is not always released, leading to a memory leak. Callers of get function 0() need to call pci dev put() to decrement the reference count and prevent the leak. The issue has been addressed by ensuring pci dev put() is called in the error path and by adding comments to inform callers about the need to release the device reference.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2026-02525
CVE-2022-50337

Affected Products

Astra Linux
Linux Kernel