CVE-2022-49684

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 26, 2025
Updated: Mar 11, 2025

Summary

CVE-2022-49684 is a vulnerability affecting the Linux kernel. This issue involves a refcount leak in the function "aspeed_adc_set_trim_data" within the "iio" driver for "aspeed" ADC chips. The problem arises because the node pointer returned by "of_find_node_by_name()" is not properly released using "of_node_put()" once the function is done with it, resulting in a refcount leak. This vulnerability has now been resolved.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share