CVE-2022-49481: regulator: pfuze100: Fix refcount leak in pfuze_parse_regulators_dt
In the Linux kernel, the following vulnerability has been resolved:
regulator: pfuze100: Fix refcount leak in pfuze_parse_regulators_dt
of_node_get() returns a node with refcount incremented.
Calling of_node_put() to drop the reference when not needed anymore.
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel availability issue caused by a small resource-management bug in the PFUZE100 regulator driver. A local, low-privileged attacker may be able to trigger resource leakage and degrade availability on affected systems. The sources do not indicate data theft, data modification, remote attack, or active exploitation.
Executive priority
Treat this as a moderate operational-risk patching item, not an emergency internet-facing breach scenario. Prioritize embedded, appliance, and hardware-specific Linux estates where the affected regulator driver may be present.
Technical view
The kernel PFUZE100 regulator parser increments a device-tree node reference with of_node_get() but failed to release it with of_node_put(). The CVSS vector is local, low complexity, low privileges, no user interaction, unchanged scope, and high availability impact only.
Likely exposure
Exposure is most likely on Linux systems running affected kernel versions or downstream kernels that include the vulnerable PFUZE100 regulator code. Practical relevance depends on kernel configuration, hardware, and device-tree use; the provided sources do not prove broad exposure across all Linux deployments.
Exploitation context
CISA KEV status is false, and the provided sources do not state active exploitation. The CVSS vector indicates local access with low privileges is required. No cited source supports remote exploitation or confidentiality or integrity impact.
Researcher notes
Evidence is limited to the CVE record and upstream stable commits. The root cause is a reference-count leak, with availability impact only per CVSS. No CWE, exploit report, affected distributions, or hardware-specific deployment evidence is included in the source bundle.
Mitigation direction
Apply the relevant upstream stable kernel fix or a vendor kernel update containing it.
Check Linux distribution or device vendor guidance for backported fixes.
Prioritize systems where PFUZE100 regulator support is enabled and used.
Retire or isolate affected unsupported kernels if no vendor update exists.
Track kernel advisories for any change in exploitation status.
Validation and detection
Inventory running kernel versions and downstream vendor kernel package versions.
Confirm whether PFUZE100 regulator support is built or loaded.
Verify the kernel source includes of_node_put() cleanup in pfuze_parse_regulators_dt.
Map installed kernels against the listed upstream stable fix references.
Document any affected embedded or appliance images separately from general servers.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49481 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.