We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-49896

cxl/pmem: Fix cxl_pmem_region and cxl_memdev leak



Description

In the Linux kernel, the following vulnerability has been resolved: cxl/pmem: Fix cxl_pmem_region and cxl_memdev leak When a cxl_nvdimm object goes through a ->remove() event (device physically removed, nvdimm-bridge disabled, or nvdimm device disabled), then any associated regions must also be disabled. As highlighted by the cxl-create-region.sh test [1], a single device may host multiple regions, but the driver was only tracking one region at a time. This leads to a situation where only the last enabled region per nvdimm device is cleaned up properly. Other regions are leaked, and this also causes cxl_memdev reference leaks. Fix the tracking by allowing cxl_nvdimm objects to track multiple region associations.

Reserved 2025-05-01 | Published 2025-05-01 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

04ad63f086d1a9649b8b082748cbc7a570ade461 before f43b6bfdbab78606735ba81185cf0602b81e40b6
affected

04ad63f086d1a9649b8b082748cbc7a570ade461 before 4d07ae22e79ebc2d7528bbc69daa53b86981cb3a
affected

Default status
affected

6.0
affected

Any version before 6.0
unaffected

6.0.8
unaffected

6.1
unaffected

References

git.kernel.org/...c/f43b6bfdbab78606735ba81185cf0602b81e40b6

git.kernel.org/...c/4d07ae22e79ebc2d7528bbc69daa53b86981cb3a

cve.org (CVE-2022-49896)

nvd.nist.gov (CVE-2022-49896)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2022-49896

Support options

Helpdesk Chat, Email, Knowledgebase