{"id":"DEBIAN-CVE-2022-49808","details":"In the Linux kernel, the following vulnerability has been resolved:  net: dsa: don't leak tagger-owned storage on switch driver unbind  In the initial commit dc452a471dba (\"net: dsa: introduce tagger-owned storage for private and shared data\"), we had a call to tag_ops-\u003edisconnect(dst) issued from dsa_tree_free(), which is called at tree teardown time.  There were problems with connecting to a switch tree as a whole, so this got reworked to connecting to individual switches within the tree. In this process, tag_ops-\u003edisconnect(ds) was made to be called only from switch.c (cross-chip notifiers emitted as a result of dynamic tag proto changes), but the normal driver teardown code path wasn't replaced with anything.  Solve this problem by adding a function that does the opposite of dsa_switch_setup_tag_protocol(), which is called from the equivalent spot in dsa_switch_teardown(). The positioning here also ensures that we won't have any use-after-free in tagging protocol (*rcv) ops, since the teardown sequence is as follows:  dsa_tree_teardown -\u003e dsa_tree_teardown_master    -\u003e dsa_master_teardown       -\u003e unsets master-\u003edsa_ptr, making no further packets match the          ETH_P_XDSA packet type handler -\u003e dsa_tree_teardown_ports    -\u003e dsa_port_teardown       -\u003e dsa_slave_destroy          -\u003e unregisters DSA net devices, there is even a synchronize_net()             in unregister_netdevice_many() -\u003e dsa_tree_teardown_switches    -\u003e dsa_switch_teardown       -\u003e dsa_switch_teardown_tag_protocol          -\u003e finally frees the tagger-owned storage","modified":"2026-08-27T23:04:30.490698595Z","published":"2025-05-01T15:16:04.130Z","upstream":["CVE-2022-49808"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49808"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49808.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49808.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49808.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}