cxl/region: Fix cxl_region leak, cleanup targets at region delete
Published May 1, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.17%
Description
When a region is deleted any targets that have been previously assigned to that region hold references to it. Trigger those references to drop by detaching all targets at unregister_region() time.
Otherwise that region object will leak as userspace has lost the ability to detach targets once region sysfs is torn down.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.0StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.0
- Version 6.0.8StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.0 · < 6.0.8
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A memory leak was fixed in the cxl_region subsystem where previously assigned endpoint decoders retained references to a deleted region object. Without explicit target detachment at the time of region removal, these references were never released, leading to a persistent leak. This issue can only be triggered by privileged users with access to region configuration via sysfs. Unprivileged users cannot create or delete CXL regions or assign decoders.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-49893 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2363455 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12891 Advisory
- https://git.kernel.org/stable/c/0d9e734018d70cecf79e2e4c6082167160a0f13f Patch
- https://git.kernel.org/stable/c/45d9fb4b758b9d602ee7776eb6754b0349946aad Patch
- https://lore.kernel.org/linux-cve-announce/2025050158-CVE-2022-49893-209a@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49893
- https://www.cve.org/CVERecord?id=CVE-2022-49893
Change history (0)
No recorded changes yet.