{"id":"DEBIAN-CVE-2022-49839","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: scsi_transport_sas: Fix error handling in sas_phy_add()  If transport_add_device() fails in sas_phy_add(), the kernel will crash trying to delete the device in transport_remove_device() called from sas_remove_host().  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000108 CPU: 61 PID: 42829 Comm: rmmod Kdump: loaded Tainted: G        W          6.1.0-rc1+ #173 pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : device_del+0x54/0x3d0 lr : device_del+0x37c/0x3d0 Call trace:  device_del+0x54/0x3d0  attribute_container_class_device_del+0x28/0x38  transport_remove_classdev+0x6c/0x80  attribute_container_device_trigger+0x108/0x110  transport_remove_device+0x28/0x38  sas_phy_delete+0x30/0x60 [scsi_transport_sas]  do_sas_phy_delete+0x6c/0x80 [scsi_transport_sas]  device_for_each_child+0x68/0xb0  sas_remove_children+0x40/0x50 [scsi_transport_sas]  sas_remove_host+0x20/0x38 [scsi_transport_sas]  hisi_sas_remove+0x40/0x68 [hisi_sas_main]  hisi_sas_v2_remove+0x20/0x30 [hisi_sas_v2_hw]  platform_remove+0x2c/0x60  Fix this by checking and handling return value of transport_add_device() in sas_phy_add().","modified":"2026-09-01T20:04:56.560135525Z","published":"2025-05-01T15:16:07.390Z","upstream":["CVE-2022-49839"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49839"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49839.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49839.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49839.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}