CVE-2022-50520

Updated: 2026-02-08 00:57:23.135584

Description:

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Fix PCI device refcount leak in radeon_atrm_get_bios() As comment of pci_get_class() says, it returns a pci_device with its refcount increased and decreased the refcount for the input parameter @from if it is not NULL. If we break the loop in radeon_atrm_get_bios() with 'pdev' not NULL, we need to call pci_dev_put() to decrease the refcount. Add the missing pci_dev_put() to avoid refcount leak.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-11-05 04:56:55 This is a refcount leak in the radeon driver’s ATRM VBIOS-fetch path, which is only exercised on s...
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-11-05 04:56:55
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-11-05 04:56:56
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Needs Triage 2026-02-09 20:05:25 This issue is a local-only reference‑count leak in the Radeon driver’s ATRM BIOS‑retrieval pat...
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Needs Triage 2026-02-09 20:05:11 This issue is a local-only reference‑count leak in the Radeon driver’s ATRM BIOS‑retrieval pat...