
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2022-49243 is a vulnerability in the Linux kernel's ASoC (ALSA System on Chip) Atmel driver. The issue was discovered in the at91sam9g20ekaudioprobe function where there was a missing ofnodeput() call, leading to a reference count leak. This vulnerability was first disclosed on February 26, 2025 (NVD).
The vulnerability exists in the sound/soc/atmel/sam9g20wm8731.c file, specifically in the at91sam9g20ekaudioprobe function. The issue occurs because a node pointer returned by ofparsephandle() with an incremented reference count wasn't properly released, causing a reference count leak. The fix involves adding an ofnodeput(codecnp) call before returning from the error path (Kernel Commit).
The vulnerability results in a kernel memory leak due to improper reference counting. While the immediate impact is a memory leak, continued exploitation could potentially lead to resource exhaustion in the kernel.
The issue has been fixed by adding the missing ofnodeput() call in the error path of at91sam9g20ekaudioprobe function. The fix was committed to the Linux kernel and backported to various stable kernel versions (Kernel Fix).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”