CVE-2022-49787

Updated: 2026-02-27 02:09:08.712712

Description:

In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-pci: Fix possible memory leak caused by missing pci_dev_put() pci_get_device() will increase the reference count for the returned pci_dev. We need to use pci_dev_put() to decrease the reference count before amd_probe() returns. There is no problem for the 'smbus_dev == NULL' branch because pci_dev_put() can also handle the NULL input parameter case.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-09-10 21:23:24 This CVE is a refcount-related memory leak confined to the sdhci‑pci MMC driver’s AMD probe path...
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-11-11 02:54:03
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-11-11 02:54:03
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Ignored 2025-11-11 02:54:40
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Ignored 2025-11-11 02:54:30