CVE-2022-49373: watchdog: ts4800_wdt: Fix refcount leak in ts4800_wdt_probe
In the Linux kernel, the following vulnerability has been resolved:
watchdog: ts4800_wdt: Fix refcount leak in ts4800_wdt_probe
of_parse_phandle() returns a node pointer with refcount
incremented, we should use of_node_put() on it when done.
Add missing of_node_put() in some error paths.
Security readout for executives and security teams
Plain-English summary
CVE-2022-49373 is a Linux kernel watchdog driver bug that can leak a device-tree node reference during driver probing error paths. The published impact is availability only, with local low-privileged access required. It is not listed as CISA KEV, and the bundle provides no evidence of active exploitation.
Executive priority
Treat this as a routine kernel availability fix unless affected embedded Linux systems with local user access are business-critical. It does not justify emergency response based on the supplied evidence, but it should be included in normal kernel patch cycles.
Technical view
The issue is in the Linux kernel ts4800_wdt watchdog driver. of_parse_phandle() increments a node reference, but some ts4800_wdt_probe error paths failed to call of_node_put(). The kernel fix adds the missing release calls. CVSS 3.1 is 5.5, local attack vector, low complexity, low privileges, no user interaction, availability high.
Likely exposure
Exposure appears limited to Linux systems running affected kernel versions where the ts4800_wdt watchdog driver is present and relevant. The source bundle lists Linux as affected and names stable kernel fix commits, but does not identify distributions, appliances, or cloud services carrying vulnerable builds.
Exploitation context
The CVSS vector requires local access with low privileges and shows no confidentiality or integrity impact. KEV is false, and the supplied sources do not claim public exploitation. Practical risk is mainly local availability degradation or failure conditions tied to the driver probe path.
Researcher notes
The evidence is narrow: a refcount leak fix in ts4800_wdt_probe error handling, mapped to CVSS availability impact. The bundle does not provide a CWE, exploit details, distribution advisories, or proof that generic Linux deployments are reachable without the specific watchdog driver context.
Mitigation direction
Update to a vendor-supported kernel containing the referenced stable fixes.
Check distribution advisories for backported fixes before relying on upstream version numbers.
Prioritize systems that expose local accounts or run affected embedded hardware.
Avoid unsupported kernel rebuilds; follow vendor kernel guidance for production systems.
Validation and detection
Inventory Linux kernel versions and vendor patch levels across affected assets.
Check whether ts4800_wdt is built, loaded, or relevant to deployed hardware.
Confirm vendor kernels include one of the referenced stable fixes or an equivalent backport.
Record KEV status as false unless new authoritative evidence appears.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49373 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.