CVE-2022-49455

Source
https://cve.org/CVERecord?id=CVE-2022-49455
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49455.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49455
Downstream
Related
Published
2025-02-26T02:13:04.116Z
Modified
2026-04-11T12:44:04.455512Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
misc: ocxl: fix possible double free in ocxl_file_register_afu
Details

In the Linux kernel, the following vulnerability has been resolved:

misc: ocxl: fix possible double free in ocxlfileregister_afu

inforelease() will be called in deviceunregister() when info->dev's reference count is 0. So there is no need to call ocxlafuput() and kfree() again.

Fix this by adding freeminor() and return to errunregister error path.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49455.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
75ca758adbafc81804c39b2c200ecdc819a6c042
Fixed
de65c32ace9aa70d51facc61ba986607075e3a25
Fixed
ee89d8dee55ab4b3b8ad8b70866b2841ba334767
Fixed
8fb674216835e1f0c143762696d645facebb4685
Fixed
252768d32e92c1214aeebb5fec0844ca479bcf5c
Fixed
9e9087cf34ee69f4e95d146ac29385d6e367a97b
Fixed
950cf957fe34d40d63dfa3bf3968210430b6491e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49455.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
5.4.198
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.121
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.46
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.17.14
Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
5.18.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49455.json"