Security Advisory

CVE-2022-49389

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-02-26 02:11:22
Last updated 2026-05-23 15:22:01
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: usb: usbip: fix a refcount leak in stub_probe() usb_get_dev() is called in stub_device_alloc(). When stub_probe() fails after that, usb_put_dev() needs to be called to release the reference. Fix this by moving usb_put_dev() to sdev_free error path handling. Find this by code review.