CVE-2022-49808
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2022-49808 affects the Linux kernel and involves a vulnerability related to tagger-owned storage leakage during switch driver unbind in the DSA (Distributed Switch Architecture) subsystem. The issue was discovered and reported on May 1, 2025 (NVD, Wiz).

Technical details

The vulnerability stems from an issue in the network DSA subsystem where tagger-owned storage is not properly freed during switch driver unbind operations. The issue originated from changes in the initial commit dc452a471dba which introduced tagger-owned storage for private and shared data. While the tag_ops->disconnect(dst) call was previously issued from dsa_tree_free() at tree teardown time, subsequent reworking of the connection process to individual switches within the tree left the normal driver teardown code path without proper cleanup (NVD, Red Hat).

Impact

The vulnerability results in a memory leak condition when unbinding switch drivers in the Linux kernel's DSA subsystem. This could potentially lead to resource exhaustion over time if the affected operations are performed repeatedly (Wiz).

Mitigation and workarounds

The issue has been resolved by adding a function that performs the opposite operation of dsa_switch_setup_tag_protocol(), which is called from the equivalent spot in dsa_switch_teardown(). The fix ensures proper cleanup sequence and prevents use-after-free conditions in tagging protocol operations (Wiz).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22776HIGH8.7
  • Linux DebianLinux Debian
  • cpp-httplib
NoNoJan 12, 2026
CVE-2026-22801MEDIUM6.8
  • OpenJDK JDKOpenJDK JDK
  • java-21-openjdk-demo-fastdebug
NoYesJan 12, 2026
CVE-2026-22695MEDIUM6.1
  • OpenJDK JDKOpenJDK JDK
  • java-25-openjdk-static-libs
NoYesJan 12, 2026
CVE-2026-22251MEDIUM5.3
  • PythonPython
  • wlc
NoYesJan 12, 2026
CVE-2026-0665N/AN/A
  • Linux DebianLinux Debian
  • qemu
NoNoJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management