VYPR
Medium severity5.5NVD Advisory· Published May 1, 2025· Updated Jun 17, 2026

CVE-2022-49895

CVE-2022-49895

Description

In the Linux kernel, the following vulnerability has been resolved:

cxl/region: Fix decoder allocation crash

When an intermediate port's decoders have been exhausted by existing regions, and creating a new region with the port in question in it's hierarchical path is attempted, cxl_port_attach_region() fails to find a port decoder (as would be expected), and drops into the failure / cleanup path.

However, during cleanup of the region reference, a sanity check attempts to dereference the decoder, which in the above case didn't exist. This causes a NULL pointer dereference BUG.

To fix this, refactor the decoder allocation and de-allocation into helper routines, and in this 'free' routine, check that the decoder, @cxld, is valid before attempting any operations on it.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Linux/Kernelllm-fuzzy6 versions
    (expand)+ 5 more
    • (no CPE)
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.0,<6.0.8
    • cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:*
    • (no CPE)range: 6.0
  • osv-coords
    Range: >= 6.0.0, < 6.0.8

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.