PT-2025-18543 · Linux+2 · Linux Kernel+2

Publicado

2022-11-11

·

Atualizado

2025-11-10

·

CVE-2022-49826

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, which was caused by a double call to ata host put() in the ata tport add() function. This led to a null pointer dereference when unbinding a device after a failure, resulting in a kernel crash. The issue occurred because the reference count of ap->host was decreased to 0, causing all ports to be freed and set to null. When ata host stop() was called to release resources, it resulted in a null pointer dereference.
Recommendations To resolve this issue, remove the redundant ata host put() call in the error path of ata tport add(). This fix will prevent the null pointer dereference and subsequent kernel crash.
Note: Since the affected versions are not explicitly specified, it is recommended to update to the latest Linux kernel version to ensure the fix is applied. However, the exact version with the fix is not provided in the input descriptions.

Exploit

Correção

NULL Pointer Dereference

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-03909
CVE-2022-49826
OESA-2025-1513
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:01982-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:01995-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_01982-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Produtos afetados

Astra Linux
Linux Kernel
Suse