{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "384e624bb211b406db40edc900bb51af8bb267d0"
            },
            {
              "fixed": "12316b9f7c18138ae656050cfd716728e27b7e2f"
            },
            {
              "fixed": "a90accb358ae33ea982a35595573f7a045993f8b"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49894.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Fix region HPA ordering validation\n\nSome regions may not have any address space allocated. Skip them when\nvalidating HPA order otherwise a crash like the following may result:\n\n devm_cxl_add_region: cxl_acpi cxl_acpi.0: decoder3.4: created region9\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n [..]\n RIP: 0010:store_targetN+0x655/0x1740 [cxl_core]\n [..]\n Call Trace:\n  \u003cTASK\u003e\n  kernfs_fop_write_iter+0x144/0x200\n  vfs_write+0x24a/0x4d0\n  ksys_write+0x69/0xf0\n  do_syscall_64+0x3a/0x90\n\nstore_targetN+0x655/0x1740:\nalloc_region_ref at drivers/cxl/core/region.c:676\n(inlined by) cxl_port_attach_region at drivers/cxl/core/region.c:850\n(inlined by) cxl_region_attach at drivers/cxl/core/region.c:1290\n(inlined by) attach_target at drivers/cxl/core/region.c:1410\n(inlined by) store_targetN at drivers/cxl/core/region.c:1453",
  "id": "CVE-2022-49894",
  "modified": "2026-04-01T23:10:34.990713117Z",
  "published": "2025-05-01T14:10:37.109Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/12316b9f7c18138ae656050cfd716728e27b7e2f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a90accb358ae33ea982a35595573f7a045993f8b"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49894.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49894"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.7.3",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "cxl/region: Fix region HPA ordering validation"
}