CVE-2022-49211: mips: cdmm: Fix refcount leak in mips_cdmm_phys_base
In the Linux kernel, the following vulnerability has been resolved:
mips: cdmm: Fix refcount leak in mips_cdmm_phys_base
The of_find_compatible_node() function returns a node pointer with
refcount incremented, We should use of_node_put() on it when done
Add the missing of_node_put() to release the refcount.
Security readout for executives and security teams
Plain-English summary
This CVE is a Linux kernel resource-management bug in MIPS CDMM handling. A missing reference release can leak kernel object references, potentially degrading availability. The published CVSS score is medium, and the attack model requires local low-privileged access.
Executive priority
Treat as a routine but real availability-risk kernel update. It is not currently evidenced as actively exploited, but systems with local multi-user access should be prioritized because the reported impact is high availability loss.
Technical view
In mips_cdmm_phys_base, of_find_compatible_node() increments a device-tree node reference count. The fix adds the missing of_node_put() when done. The reported impact is availability only, with CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.
Likely exposure
Exposure is most relevant to Linux systems using affected MIPS kernel code. The source bundle lists Linux kernel versions including 5.9, 5.10.110, 5.15.33, 5.16.19, 5.17.2, and 5.18 as affected or boundary versions.
Exploitation context
The bundle does not show CISA KEV listing or public active exploitation. The CVSS vector indicates exploitation requires local access with low privileges and does not require user interaction. No exploit details are provided in the sources.
Researcher notes
Evidence is limited to the CVE description, CVSS metadata, and kernel stable fix references. The root cause is a reference-count leak, not a confidentiality or integrity issue. No CWE, exploit status, or vendor-specific package fix data is included in the bundle.
Mitigation direction
Inventory Linux systems using MIPS kernels or MIPS CDMM support.
Apply a vendor kernel update containing the referenced stable fixes.
If using custom kernels, confirm the of_node_put() fix is present.
Prioritize systems with untrusted local users or shared shell access.
Track Linux distribution advisories for packaged kernel availability.
Validation and detection
Map deployed kernel versions against the affected versions in the CVE record.
Check whether the referenced stable commit is included in your kernel tree.
Confirm MIPS CDMM code is relevant to the deployed platform.
Review kernel package changelogs for CVE-2022-49211 or the fix title.
Monitor local-user-facing systems for availability anomalies until patched.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49211 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.