CVE-2022-49462: drm/msm/a6xx: Fix refcount leak in a6xx_gpu_init
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/a6xx: Fix refcount leak in a6xx_gpu_init
of_parse_phandle() returns a node pointer with refcount
incremented, we should use of_node_put() on it when not need anymore.
a6xx_gmu_init() passes the node to of_find_device_by_node()
and of_dma_configure(), of_find_device_by_node() will takes its
reference, of_dma_configure() doesn't need the node after usage.
Add missing of_node_put() to avoid refcount leak.
Security readout for executives and security teams
Plain-English summary
CVE-2022-49462 is a Linux kernel resource-management bug in the MSM A6xx GPU driver. A missing reference release can leak kernel object references. The published impact is availability only, requiring local low-privileged access. Treat it as a stability and uptime risk for affected Linux systems, not as a confirmed data-theft issue.
Executive priority
Handle through normal kernel patch management unless the environment has high-density shared systems, untrusted local users, or uptime-sensitive workloads using affected hardware. No source evidence supports emergency exploitation response.
Technical view
The issue is in drm/msm/a6xx_gpu_init handling. of_parse_phandle() increments a device-tree node reference, but the vulnerable code did not release it with of_node_put() after use. The Linux stable fixes add the missing release around a6xx_gmu_init behavior involving of_find_device_by_node() and of_dma_configure().
Likely exposure
Exposure appears limited to Linux systems running affected kernel branches with the Qualcomm MSM A6xx GPU driver path. The source bundle lists Linux kernel versions and stable commits, but does not identify specific distributions, devices, or downstream vendor package names.
Exploitation context
The CVSS vector is local, low complexity, low privileges, no user interaction, and high availability impact. The bundle marks KEV as false and provides no cited evidence of active exploitation or public weaponization.
Researcher notes
The source evidence is narrow: a kernel refcount leak fix and CVSS metadata. It supports local availability risk, but not confidentiality, integrity impact, exploit maturity, affected distributions, or device-specific exposure beyond Linux MSM A6xx driver context.
Mitigation direction
Upgrade to a Linux kernel containing the relevant stable fix or vendor backport.
Check your Linux distribution or device vendor advisory for patched kernel packages.
Prioritize internet-facing or multi-user systems where local users or workloads are less trusted.
Track affected kernel branches against the cited Linux stable commits.
Validation and detection
Inventory Linux kernel versions across systems that may use MSM A6xx GPU support.
Confirm whether the running kernel includes the stable fix or downstream backport.
Verify whether affected DRM MSM A6xx driver code is built or deployed.
Record compensating controls for systems awaiting vendor kernel updates.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49462 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.