{"schema_version":"1.9.0","id":"CVE-2022-50481","published":"2025-10-04T15:16:40.374Z","modified":"2026-08-12T03:51:11.616046924Z","related":["SUSE-SU-2025:4189-1"],"summary":"cxl: fix possible null-ptr-deref in cxl_guest_init_afu|adapter()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl: fix possible null-ptr-deref in cxl_guest_init_afu|adapter()\n\nIf device_register() fails in cxl_register_afu|adapter(), the device\nis not added, device_unregister() can not be called in the error path,\notherwise it will cause a null-ptr-deref because of removing not added\ndevice.\n\nAs comment of device_register() says, it should use put_device() to give\nup the reference in the error path. So split device_unregister() into\ndevice_del() and put_device(), then goes to put dev when register fails.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"14baf4d9c739e6e69150512d2eb23c71fffcc192"},{"fixed":"96fba6fb95bdede80583c262ac185da09661f264"},{"fixed":"1ae581696b7a799afa39a664c4b721569643f58a"},{"fixed":"d775a1da5a52b4f4bb02f2707ba420d1bec48dbb"},{"fixed":"60b2ed21a65f3f5318666ccd765c3507991370cf"},{"fixed":"170e8c2d2b61e15e7f7cfeded81bc1e959a15ed8"},{"fixed":"e5021bbf11b024cc65ea1e84c377df484183be4b"},{"fixed":"b32559ee4e6667c5c3daf4ec5454c277d1f255d2"},{"fixed":"ab44c182353be101c3be9465e1d15d42130c53c4"},{"fixed":"61c80d1c3833e196256fb060382db94f24d3d9a7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50481.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.6.0"},{"fixed":"4.9.337"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.10.0"},{"fixed":"4.14.303"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.19.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.4.229"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.163"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.86"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.0.16"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50481.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/170e8c2d2b61e15e7f7cfeded81bc1e959a15ed8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1ae581696b7a799afa39a664c4b721569643f58a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/60b2ed21a65f3f5318666ccd765c3507991370cf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/61c80d1c3833e196256fb060382db94f24d3d9a7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/96fba6fb95bdede80583c262ac185da09661f264"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ab44c182353be101c3be9465e1d15d42130c53c4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b32559ee4e6667c5c3daf4ec5454c277d1f255d2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d775a1da5a52b4f4bb02f2707ba420d1bec48dbb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e5021bbf11b024cc65ea1e84c377df484183be4b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50481.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-50481"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50481.json"}}