CVE-2022-49528

MEDIUM

Linux Kernel 4.13-5.18.2 - Resource Leak via Failed Probe in DW9714 Driver

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: i2c: dw9714: Disable the regulator when the driver fails to probe When the driver fails to probe, we will get the following splat: [ 59.305988] ------------[ cut here ]------------ [ 59.306417] WARNING: CPU: 2 PID: 395 at drivers/regulator/core.c:2257 _regulator_put+0x3ec/0x4e0 [ 59.310345] RIP: 0010:_regulator_put+0x3ec/0x4e0 [ 59.318362] Call Trace: [ 59.318582] <TASK> [ 59.318765] regulator_put+0x1f/0x30 [ 59.319058] devres_release_group+0x319/0x3d0 [ 59.319420] i2c_device_probe+0x766/0x940 Fix this by disabling the regulator in error handling.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (8)
linux/Kernel 4.13.0 - 5.18.3linux
Linux/Linux < 4.13
Linux/Linux 4.13
Linux/Linux 5.18.3 - 5.18.*
Linux/Linux 5.19
Linux/Linux cc95d3423c6786d61e3c52898ed69955077f41a6 - 02276e18defa2fccf16413b44440277d98c2b1ea
Linux/Linux cc95d3423c6786d61e3c52898ed69955077f41a6 - fa83ea1de5b3efd87fe01408d5db1fd2ff4767fa
linux/linux_kernel 4.13 - 5.18.3
Published Feb 26, 2025
Tracked Since Feb 18, 2026