{"id":"DEBIAN-CVE-2022-49118","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: hisi_sas: Free irq vectors in order for v3 HW  If the driver probe fails to request the channel IRQ or fatal IRQ, the driver will free the IRQ vectors before freeing the IRQs in free_irq(), and this will cause a kernel BUG like this:  ------------[ cut here ]------------ kernel BUG at drivers/pci/msi.c:369! Internal error: Oops - BUG: 0 [#1] PREEMPT SMP Call trace:    free_msi_irqs+0x118/0x13c    pci_disable_msi+0xfc/0x120    pci_free_irq_vectors+0x24/0x3c    hisi_sas_v3_probe+0x360/0x9d0 [hisi_sas_v3_hw]    local_pci_probe+0x44/0xb0    work_for_cpu_fn+0x20/0x34    process_one_work+0x1d0/0x340    worker_thread+0x2e0/0x460    kthread+0x180/0x190    ret_from_fork+0x10/0x20 ---[ end trace b88990335b610c11 ]---  So we use devm_add_action() to control the order in which we free the vectors.","modified":"2026-09-01T20:04:52.215510521Z","published":"2025-02-26T07:00:49.150Z","upstream":["CVE-2022-49118"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49118"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49118.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49118.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49118.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}