{"schema_version":"1.9.0","id":"CVE-2022-49731","published":"2025-02-26T02:24:41.300Z","modified":"2026-08-12T03:51:15.864473300Z","related":["SUSE-SU-2025:02334-1","SUSE-SU-2025:1027-1","SUSE-SU-2025:1176-1","SUSE-SU-2025:1183-1","SUSE-SU-2025:1194-1","SUSE-SU-2025:1241-1","SUSE-SU-2025:1263-1"],"summary":"ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo()\n\nIn an unlikely (and probably wrong?) case that the 'ppi' parameter of\nata_host_alloc_pinfo() points to an array starting with a NULL pointer,\nthere's going to be a kernel oops as the 'pi' local variable won't get\nreassigned from the initial value of NULL. Initialize 'pi' instead to\n'&ata_dummy_port_info' to fix the possible kernel oops for good...\n\nFound by Linux Verification Center (linuxtesting.org) with the SVACE static\nanalysis tool.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f5cda257296fbd3683b1f568f2d94d3caaacf74d"},{"fixed":"ca4693e6e06e4fd2b240c0fec47aa2498c94848e"},{"fixed":"1ac5efee33f29e704226506d429b84575a5d66f8"},{"fixed":"a810bd5af06977a847d1f202b22d7defd5c62497"},{"fixed":"253334f84c81bc6a43af489f108c0bddad989eef"},{"fixed":"36cd19e7d4e5571d77a2ed20c5b6ef50cf57734a"},{"fixed":"ff128fbea720bf763fa345680dda5f050bc24a47"},{"fixed":"07cbdb4807d369fbda73062a91b570c4dc5ec429"},{"fixed":"bf476fe22aa1851bab4728e0c49025a6a0bea307"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49731.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.22"},{"fixed":"4.9.320"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.10.0"},{"fixed":"4.14.285"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.19.249"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.4.200"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.124"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.49"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"5.18.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49731.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/07cbdb4807d369fbda73062a91b570c4dc5ec429"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1ac5efee33f29e704226506d429b84575a5d66f8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/253334f84c81bc6a43af489f108c0bddad989eef"},{"type":"WEB","url":"https://git.kernel.org/stable/c/36cd19e7d4e5571d77a2ed20c5b6ef50cf57734a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a810bd5af06977a847d1f202b22d7defd5c62497"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bf476fe22aa1851bab4728e0c49025a6a0bea307"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ca4693e6e06e4fd2b240c0fec47aa2498c94848e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ff128fbea720bf763fa345680dda5f050bc24a47"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49731.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-49731"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49731.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}