CVE-2022-49894

MEDIUM

Linux Kernel 6.0-6.0.8 - NULL Pointer Dereference in CXL Region HPA Order Validation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix region HPA ordering validation Some regions may not have any address space allocated. Skip them when validating HPA order otherwise a crash like the following may result: devm_cxl_add_region: cxl_acpi cxl_acpi.0: decoder3.4: created region9 BUG: kernel NULL pointer dereference, address: 0000000000000000 [..] RIP: 0010:store_targetN+0x655/0x1740 [cxl_core] [..] Call Trace: <TASK> kernfs_fop_write_iter+0x144/0x200 vfs_write+0x24a/0x4d0 ksys_write+0x69/0xf0 do_syscall_64+0x3a/0x90 store_targetN+0x655/0x1740: alloc_region_ref at drivers/cxl/core/region.c:676 (inlined by) cxl_port_attach_region at drivers/cxl/core/region.c:850 (inlined by) cxl_region_attach at drivers/cxl/core/region.c:1290 (inlined by) attach_target at drivers/cxl/core/region.c:1410 (inlined by) store_targetN at drivers/cxl/core/region.c:1453

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (9)
linux/Kernel 6.0.0 - 6.0.8linux
Linux/Linux < 6.0
Linux/Linux 384e624bb211b406db40edc900bb51af8bb267d0 - 12316b9f7c18138ae656050cfd716728e27b7e2f
Linux/Linux 384e624bb211b406db40edc900bb51af8bb267d0 - a90accb358ae33ea982a35595573f7a045993f8b
Linux/Linux 6.0
Linux/Linux 6.0.8 - 6.0.*
Linux/Linux 6.1
linux/linux_kernel 6.1 rc1 (3 CPE variants)
linux/linux_kernel 6.0 - 6.0.8
Published May 01, 2025
Tracked Since Feb 18, 2026