{"id":"DEBIAN-CVE-2022-48707","details":"In the Linux kernel, the following vulnerability has been resolved:  cxl/region: Fix null pointer dereference for resetting decoder  Not all decoders have a reset callback.  The CXL specification allows a host bridge with a single root port to have no explicit HDM decoders. Currently the region driver assumes there are none.  As such the CXL core creates a special pass through decoder instance without a commit/reset callback.  Prior to this patch, the -\u003ereset() callback was called unconditionally when calling cxl_region_decode_reset. Thus a configuration with 1 Host Bridge, 1 Root Port, and one directly attached CXL type 3 device or multiple CXL type 3 devices attached to downstream ports of a switch can cause a null pointer dereference.  Before the fix, a kernel crash was observed when we destroy the region, and a pass through decoder is reset.  The issue can be reproduced as below,     1) create a region with a CXL setup which includes a HB with a     single root port under which a memdev is attached directly.     2) destroy the region with cxl destroy-region regionX -f.","modified":"2026-09-01T20:04:50.606738511Z","published":"2024-05-21T16:15:12.173Z","upstream":["CVE-2022-48707"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-48707"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48707.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48707.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48707.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}