5.5

CVE-2022-49000

iommu/vt-d: Fix PCI device refcount leak in has_external_pci()

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Fix PCI device refcount leak in has_external_pci()

for_each_pci_dev() is implemented by pci_get_device(). The comment of
pci_get_device() says that it will increase the reference count for the
returned pci_dev and also decrease the reference count for the input
pci_dev @from if it is not NULL.

If we break for_each_pci_dev() loop with pdev not NULL, we need to call
pci_dev_put() to decrease the reference count. Add the missing
pci_dev_put() before 'return true' to avoid reference count leak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.0 < 5.10.158
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.82
Linux ≫ Linux Kernel Version >= 5.16 < 6.0.12
Linux ≫ Linux Kernel Version 6.1 Update rc1
Linux ≫ Linux Kernel Version 6.1 Update rc2
Linux ≫ Linux Kernel Version 6.1 Update rc3
Linux ≫ Linux Kernel Version 6.1 Update rc4
Linux ≫ Linux Kernel Version 6.1 Update rc5
Linux ≫ Linux Kernel Version 6.1 Update rc6
Linux ≫ Linux Kernel Version 6.1 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.154
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/10ed7655a17f6a3eaecd1293830488259ccd5723
Patch
https://git.kernel.org/stable/c/17f67414718e6aba123335a33b7d15aa594fff34
Patch
https://git.kernel.org/stable/c/afca9e19cc720bfafc75dc5ce429c185ca93f31d
Patch
https://git.kernel.org/stable/c/b6eea8b2e858a20ad58ac62dc2de90fea2413f94
Patch