PT-2025-8323 · Linux+3 · Linux Kernel+3

Hangyu Hua

·

Published

2022-11-15

·

Updated

2025-09-29

·

CVE-2022-49389

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A refcount leak was found in the Linux kernel's usbip stub probe() function. The issue occurs when usb get dev() is called in stub device alloc() and stub probe() fails afterwards, requiring usb put dev() to be called to release the reference. This was fixed by moving usb put dev() to the sdev free error path handling.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2025_16880
CVE-2022-49389
OESA-2025-1408
OPENSUSE-SU-2025_1263-1
RHSA-2022:8267
RHSA-2022_8267
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse