CVE-2022-49568
published 2025-02-26CVE-2022-49568: In the Linux kernel, the following vulnerability has been resolved: KVM: Don't null dereference ops->destroy A KVM device cleanup happens in either of two…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
22.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
KVM: Don't null dereference ops->destroy
A KVM device cleanup happens in either of two callbacks:
1) destroy() which is called when the VM is being destroyed;
2) release() which is called when a device fd is closed.
Most KVM devices use 1) but Book3s's interrupt controller KVM devices
(XICS, XIVE, XIVE-native) use 2) as they need to close and reopen during
the machine execution. The error handling in kvm_ioctl_create_device()
assumes destroy() is always defined which leads to NULL dereference as
discovered by Syzkaller.
This adds a checks for destroy!=NULL and adds a missing release().
This is not changing kvm_destroy_devices() as devices with defined
release() should have been removed from the KVM devices list by then.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.16-1 (bookworm) | linux 5.18.16-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 852b6d57dc7fa378019786fa84727036e56839ea < 170465715a60cbb7876e6b961b21bd3225469da8 | 170465715a60cbb7876e6b961b21bd3225469da8 |
| linux | linux | >= 852b6d57dc7fa378019786fa84727036e56839ea < 3616776bc51cd3262bb1be60cc01c72e0a1959cf | 3616776bc51cd3262bb1be60cc01c72e0a1959cf |
| linux | linux | >= 852b6d57dc7fa378019786fa84727036e56839ea < e91665fbbf3ccb268b268a7d71a6513538d813ac | e91665fbbf3ccb268b268a7d71a6513538d813ac |
| linux | linux | >= 852b6d57dc7fa378019786fa84727036e56839ea < d4a5a79b780891c5cbdfdc6124d46fdf8d13dba1 | d4a5a79b780891c5cbdfdc6124d46fdf8d13dba1 |
| linux | linux | >= 852b6d57dc7fa378019786fa84727036e56839ea < e8bc2427018826e02add7b0ed0fc625a60390ae5 | e8bc2427018826e02add7b0ed0fc625a60390ae5 |
| linux | linux_kernel | < 5.4.210 | 5.4.210 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.136-1 | 5.10.136-1 |
| linux | linux_kernel | >= 0 < 5.18.16-1 | 5.18.16-1 |
| linux | linux_kernel | >= 0 < 5.18.16-1 | 5.18.16-1 |
| linux | linux_kernel | >= 0 < 5.18.16-1 | 5.18.16-1 |
| linux | linux_kernel | >= 5.11 < 5.15.58 | 5.15.58 |
| linux | linux_kernel | >= 5.16 < 5.18.15 | 5.18.15 |
| linux | linux_kernel | >= 5.5 < 5.10.134 | 5.10.134 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: KVM: Don't null dereference ops->destroy
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49568 [MEDIUM] CWE-476 kernel: KVM: Don't null dereference ops->destroy
kernel: KVM: Don't null dereference ops->destroy
In the Linux kernel, the following vulnerability has been resolved:
KVM: Don't null dereference ops->destroy
A KVM device cleanup happens in either of two callbacks:
1) destroy() which is called when the VM is being destroyed;
2) release() which is called when a device fd is closed.
Most KVM devices use 1) but Book3s's interrupt controller KVM devices
(XICS, XIVE, XIVE-native) use 2) as they need to close and reopen during
the machine execution. The error handling in kvm_ioctl_create_device()
assumes destroy() is always defined which leads to NULL dereference as
discovered by Syzkaller.
This adds a checks for destroy!=NULL and adds a missing release().
This is not changing kvm_destroy_devices() as devices with defined
release() should have
Debian
CVE-2022-49568: linux - In the Linux kernel, the following vulnerability has been resolved: KVM: Don't ...
vendor_debian·2022·CVSS 5.5
CVE-2022-49568 [MEDIUM] CVE-2022-49568: linux - In the Linux kernel, the following vulnerability has been resolved: KVM: Don't ...
In the Linux kernel, the following vulnerability has been resolved: KVM: Don't null dereference ops->destroy A KVM device cleanup happens in either of two callbacks: 1) destroy() which is called when the VM is being destroyed; 2) release() which is called when a device fd is closed. Most KVM devices use 1) but Book3s's interrupt controller KVM devices (XICS, XIVE, XIVE-native) use 2) as they need to close and reopen during the machine execution. The error handling in kvm_ioctl_create_device() assumes destroy() is always defined which leads to NULL dereference as discovered by Syzkaller. This adds a checks for destroy!=NULL and adds a missing release(). This is not changing kvm_destroy_devices() as devices with defined release() should have been removed from the KVM devices list by then.
Sc
GHSA
GHSA-vpqc-5phg-hjvg: In the Linux kernel, the following vulnerability has been resolved:
KVM: Don't null dereference ops->destroy
A KVM device cleanup happens in either
ghsa_unreviewed·2025-03-10
CVE-2022-49568 [MEDIUM] CWE-476 GHSA-vpqc-5phg-hjvg: In the Linux kernel, the following vulnerability has been resolved:
KVM: Don't null dereference ops->destroy
A KVM device cleanup happens in either
In the Linux kernel, the following vulnerability has been resolved:
KVM: Don't null dereference ops->destroy
A KVM device cleanup happens in either of two callbacks:
1) destroy() which is called when the VM is being destroyed;
2) release() which is called when a device fd is closed.
Most KVM devices use 1) but Book3s's interrupt controller KVM devices
(XICS, XIVE, XIVE-native) use 2) as they need to close and reopen during
the machine execution. The error handling in kvm_ioctl_create_device()
assumes destroy() is always defined which leads to NULL dereference as
discovered by Syzkaller.
This adds a checks for destroy!=NULL and adds a missing release().
This is not changing kvm_destroy_devices() as devices with defined
release() should have been removed from the KVM devices list by the
OSV
CVE-2022-49568: In the Linux kernel, the following vulnerability has been resolved: KVM: Don't null dereference ops->destroy A KVM device cleanup happens in either of
osv·2025-02-26·CVSS 5.5
CVE-2022-49568 [MEDIUM] CVE-2022-49568: In the Linux kernel, the following vulnerability has been resolved: KVM: Don't null dereference ops->destroy A KVM device cleanup happens in either of
In the Linux kernel, the following vulnerability has been resolved: KVM: Don't null dereference ops->destroy A KVM device cleanup happens in either of two callbacks: 1) destroy() which is called when the VM is being destroyed; 2) release() which is called when a device fd is closed. Most KVM devices use 1) but Book3s's interrupt controller KVM devices (XICS, XIVE, XIVE-native) use 2) as they need to close and reopen during the machine execution. The error handling in kvm_ioctl_create_device() assumes destroy() is always defined which leads to NULL dereference as discovered by Syzkaller. This adds a checks for destroy!=NULL and adds a missing release(). This is not changing kvm_destroy_devices() as devices with defined release() should have been removed from the KVM devices list by then.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/170465715a60cbb7876e6b961b21bd3225469da8https://git.kernel.org/stable/c/3616776bc51cd3262bb1be60cc01c72e0a1959cfhttps://git.kernel.org/stable/c/d4a5a79b780891c5cbdfdc6124d46fdf8d13dba1https://git.kernel.org/stable/c/e8bc2427018826e02add7b0ed0fc625a60390ae5https://git.kernel.org/stable/c/e91665fbbf3ccb268b268a7d71a6513538d813ac
2025-02-26
Published