CVE-2023-22996: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference after use, e.g., with put_device.

Affected products

  • Linux Linux Kernel: before 5.17.2 (fixed in 5.17.2)

Published 2023-02-28. Last modified 2026-06-17.