Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-50505— iommu/amd: Fix pci device refcount leak in ppr_notifier()

EPSS 0.02% · P4

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinuxdaae2d25a4779b272a66ddd01f5810bcee822b9e< bdb2113dd8f17a3cc84a2b4be4968a849f69ec72affected
daae2d25a4779b272a66ddd01f5810bcee822b9e< efd50c65fd1cdef63eb58825f3fe72496443764caffected
daae2d25a4779b272a66ddd01f5810bcee822b9e< 8581ec1feb895ff596fe3d326d9ba320083290aaaffected
daae2d25a4779b272a66ddd01f5810bcee822b9e< 03f51c72997559e73b327608f0cccfded715c9a0affected
daae2d25a4779b272a66ddd01f5810bcee822b9e< 6e501b3fd7a2e1c4372d72bc70717aaca2beb8a5affected
daae2d25a4779b272a66ddd01f5810bcee822b9e< 902cc2507091a81643502d8ceb0e2f105e902518affected
daae2d25a4779b272a66ddd01f5810bcee822b9e< b0637f4bd426925f5c3a15e8f8e36190fe06bac5affected
daae2d25a4779b272a66ddd01f5810bcee822b9e< 6cf0981c2233f97d56938d9d61845383d6eb227caffected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-50505

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
iommu/amd: Fix pci device refcount leak in ppr_notifier()
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix pci device refcount leak in ppr_notifier() As comment of pci_get_domain_bus_and_slot() says, it returns a pci device with refcount increment, when finish using it, the caller must decrement the reference count by calling pci_dev_put(). So call it before returning from ppr_notifier() to avoid refcount leak.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未正确释放PCI设备引用计数,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux daae2d25a4779b272a66ddd01f5810bcee822b9e ~ bdb2113dd8f17a3cc84a2b4be4968a849f69ec72 -
LinuxLinux 4.14 -

II. Public POCs for CVE-2022-50505

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-50505

登录查看更多情报信息。
Patch · 7Other · 1

Same Patch Batch · Linux · 2025-10-04 · 144 CVEs total

CVE-2025-399469.8 CRITICALtls: make sure to abort the stream if headers are bogus
CVE-2022-50489drm/mipi-dsi: Detach devices when removing the host
CVE-2023-53581net/mlx5e: Check for NOT_READY flag state after locking
CVE-2023-53580USB: Gadget: core: Help prevent panic during UVC unconfigure
CVE-2022-50507fs/ntfs3: Validate data run offset
CVE-2022-50508wifi: mt76: mt76x0: fix oob access in mt76x0_phy_get_target_power
CVE-2022-50506drbd: only clone bio if we have a backing device
CVE-2022-50504powerpc/rtas: avoid scheduling in rtas_os_term()
CVE-2022-50503mtd: lpddr2_nvm: Fix possible null-ptr-deref
CVE-2022-50501media: coda: Add check for dcoda_iram_alloc
CVE-2022-50500netdevsim: fix memory leak in nsim_drv_probe() when nsim_dev_resources_register() failed
CVE-2022-50499media: dvb-core: Fix double free in dvb_register_device()
CVE-2022-50497binfmt_misc: fix shift-out-of-bounds in check_special_flags
CVE-2022-50498eth: alx: take rtnl_lock on resume
CVE-2022-50496dm cache: Fix UAF in destroy()
CVE-2022-50494thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
CVE-2022-50493scsi: qla2xxx: Fix crash when I/O abort times out
CVE-2022-50492drm/msm: fix use-after-free on probe deferral
CVE-2022-50490bpf: Propagate error from htab_lock_bucket() to userspace
CVE-2023-53570wifi: nl80211: fix integer overflow in nl80211_parse_mbssid_elems()

Showing top 20 of 144 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-50505

No comments yet


Leave a comment