Answer in brief
CVE-2022-49137 records a Unknown severity vulnerability in drm/amd/amdgpu/amdgpu_cs: fix refcount leak of a dma_fence obj. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2022-49137 records a Unknown severity vulnerability in drm/amd/amdgpu/amdgpu_cs: fix refcount leak of a dma_fence obj. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <72d77ddb2224ebc00648f4f78f8a9a259dccbdf7 || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <4009f104b02b223d1a11d74b36b1cc083bc37028 || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <927beb05aaa429c883cc0ec6adc48964b187e291 || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <3edd8646cb7c11b57c90e026bda6f21076223f5b || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <b6d1f7d97c81ebaf2cda9c4c943ee2e484fffdcf || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <bc2d5c0775c839e2b072884f4ee6a93ba410f107 || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <dfced44f122c500004a48ecc8db516bb6a295a1b | 72d77ddb2224ebc00648f4f78f8a9a259dccbdf7, 4009f104b02b223d1a11d74b36b1cc083bc37028, 927beb05aaa429c883cc0ec6adc48964b187e291, 3edd8646cb7c11b57c90e026bda6f21076223f5b, b6d1f7d97c81ebaf2cda9c4c943ee2e484fffdcf, bc2d5c0775c839e2b072884f4ee6a93ba410f107, dfced44f122c500004a48ecc8db516bb6a295a1b |
| Linux/Linuxgeneric | 4.15 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdgpu/amdgpu_cs: fix refcount leak of a dma_fence obj This issue takes place in an error path in amdgpu_cs_fence_to_handle_ioctl(). When `info->in.what` falls into default case, the function simply returns -EINVAL, forgetting to decrement the reference count of a dma_fence obj, which is bumped earlier by amdgpu_cs_get_fence(). This may result in reference count leaks. Fix it by decreasing the refcount of specific object before returning the error code.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <72d77ddb2224ebc00648f4f78f8a9a259dccbdf7 || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <4009f104b02b223d1a11d74b36b1cc083bc37028 || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <927beb05aaa429c883cc0ec6adc48964b187e291 || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <3edd8646cb7c11b57c90e026bda6f21076223f5b || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <b6d1f7d97c81ebaf2cda9c4c943ee2e484fffdcf || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <bc2d5c0775c839e2b072884f4ee6a93ba410f107 || >=7ca24cf2d2269bde25e21c02a77fe81995a081ae <dfced44f122c500004a48ecc8db516bb6a295a1b | 72d77ddb2224ebc00648f4f78f8a9a259dccbdf7, 4009f104b02b223d1a11d74b36b1cc083bc37028, 927beb05aaa429c883cc0ec6adc48964b187e291, 3edd8646cb7c11b57c90e026bda6f21076223f5b, b6d1f7d97c81ebaf2cda9c4c943ee2e484fffdcf, bc2d5c0775c839e2b072884f4ee6a93ba410f107, dfced44f122c500004a48ecc8db516bb6a295a1b |
| Linux/Linuxgeneric | 4.15 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdgpu/amdgpu_cs: fix refcount leak of a dma_fence obj This issue takes place in an error path in amdgpu_cs_fence_to_handle_ioctl(). When `info->in.what` falls into default case, the function simply returns -EINVAL, forgetting to decrement the reference count of a dma_fence obj, which is bumped earlier by amdgpu_cs_get_fence(). This may result in reference count leaks. Fix it by decreasing the refcount of specific object before returning the error code.
Quoted source text, attributed separately from HOL analysis.