VYPR
Medium severity5.5NVD Advisory· Published May 1, 2025· Updated Jun 17, 2026

CVE-2022-49896

CVE-2022-49896

Description

In the Linux kernel, the following vulnerability has been resolved:

cxl/pmem: Fix cxl_pmem_region and cxl_memdev leak

When a cxl_nvdimm object goes through a ->remove() event (device physically removed, nvdimm-bridge disabled, or nvdimm device disabled), then any associated regions must also be disabled. As highlighted by the cxl-create-region.sh test [1], a single device may host multiple regions, but the driver was only tracking one region at a time. This leads to a situation where only the last enabled region per nvdimm device is cleaned up properly. Other regions are leaked, and this also causes cxl_memdev reference leaks.

Fix the tracking by allowing cxl_nvdimm objects to track multiple region associations.

Affected products

7
  • Linux/Kernelllm-fuzzy6 versions
    (expand)+ 5 more
    • (no CPE)
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.0,<6.0.8
    • cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:*
    • (no CPE)range: 6.0
  • osv-coords
    Range: >= 6.0.0, < 6.0.8

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.