Security Advisory

CVE-2022-49134

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-02-26 01:55:08
Last updated 2026-05-11 18:53:49
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum: Guard against invalid local ports When processing events generated by the devices firmware, the driver protects itself from events reported for non-existent local ports, but not for the CPU port (local port 0), which exists, but does not have all the fields as any local port. This can result in a NULL pointer dereference when trying access struct mlxsw_sp_port fields which are not initialized for CPU port. Commit 63b08b1f6834 ("mlxsw: spectrum: Protect driver from buggy firmware") already handled such issue by bailing early when processing a PUDE event reported for the CPU port. Generalize the approach by moving the check to a common function and making use of it in all relevant places.