CVE-2022-49895
cxl/region: Fix decoder allocation crash
Published:
5/1/2025
Last updated:
10/1/2025
Reserved:
5/1/2025
In the Linux kernel, the following vulnerability has been resolved:
cxl/region: Fix decoder allocation crash
When an intermediate port's decoders have been exhausted by existing
regions, and creating a new region with the port in question in it's
hierarchical path is attempted, cxl_port_attach_region() fails to find a
port decoder (as would be expected), and drops into the failure / cleanup
path.
However, during cleanup of the region reference, a sanity check attempts
to dereference the decoder, which in the above case didn't exist. This
causes a NULL pointer dereference BUG.
To fix this, refactor the decoder allocation and de-allocation into
helper routines, and in this 'free' routine, check that the decoder,
@cxld, is valid before attempting any operations on it.
CNA assigner:
Linux (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
Requested by:
n/a
Products affected (4)
| Product |
Vendor |
Version |
| Linux |
Linux
|
VVMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2)
|
| Linux |
Linux
|
v2.0.03P and earlier
|
| Linux |
Linux
|
Android-13
|
| Linux |
Linux
|
12.2.0.1
|