CVE-2022-49128: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: Add missing pm_runtime_put_sync pm_runtime_get_sync() will increase the rumtime PM counter even when it returns an error. Thus a pairing decrement is needed to prevent refcount leak. Fix this by replacing this API with pm_runtime_resume_and_get(), which will not change the runtime PM counter on error. Besides, a matching decrement is needed on the error handling path to keep the counter balanced.

Affected products

  • Linux Linux Kernel: before 5.15.34 (fixed in 5.15.34); from 5.16, before 5.16.20 (fixed in 5.16.20); from 5.17, before 5.17.3 (fixed in 5.17.3)

Published 2025-02-26. Last modified 2026-06-17.