PT-2025-18543 · Linux+2 · Linux Kernel+2

Published

2022-11-11

·

Updated

2025-11-10

·

CVE-2022-49826

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, which was caused by a double call to ata host put() in the ata tport add() function. This led to a null pointer dereference when unbinding a device after a failure, resulting in a kernel crash. The issue occurred because the reference count of ap->host was decreased to 0, causing all ports to be freed and set to null. When ata host stop() was called to release resources, it resulted in a null pointer dereference.
Recommendations To resolve this issue, remove the redundant ata host put() call in the error path of ata tport add(). This fix will prevent the null pointer dereference and subsequent kernel crash.
Note: Since the affected versions are not explicitly specified, it is recommended to update to the latest Linux kernel version to ensure the fix is applied. However, the exact version with the fix is not provided in the input descriptions.

Exploit

Fix

NULL Pointer Dereference

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03909
CVE-2022-49826
OESA-2025-1513
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:01982-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:01995-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_01982-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Affected Products

Astra Linux
Linux Kernel
Suse