---
id: CVE-2022-49286
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  tpm: use try_get_ops() in tpm-space.c

  As part of the series conversion to remove nested TPM operations:

  https://lore.kernel.org/all/20190205224723.19671-1-jarkko.sakk…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  tpm: use try_get_ops() in tpm-space.c

  As part of the series conversion to remove nested TPM operations:

  https://lore.kernel.org/all/20190205224723.19671-1-jarkko.sakk…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.12, < 5.4.188'
  - 'linux_kernel >= 5.5, < 5.10.109'
  - 'linux_kernel >= 5.11, < 5.15.32'
  - 'linux_kernel >= 5.16, < 5.16.18'
  - linux_kernel = 5.17
patched:
  - linux_kernel 5.16.18
published: '2025-02-26'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-49286'
references:
  - url: 'https://git.kernel.org/stable/c/476ddd23f818fb94cf86fb5617f3bb9a7c92113d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5b1d2561a03e534064b51c50c774657833d3d2cf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/95193d12f10a8a088843b25e0f5fe1d83ec6b079'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ba84f9a48366dcc3cdef978599433efe101dd5bd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eda1662cce964c8a65bb86321f8d9cfa6e9ceaab'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fb5abce6b2bb5cb3d628aaa63fa821da8c4600f9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00238
epssPercentile: 0.13221
ingestedAt: '2026-08-13T00:57:22.944Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

tpm: use try_get_ops() in tpm-space.c

As part of the series conversion to remove nested TPM operations:

https://lore.kernel.org/all/20190205224723.19671-1-jarkko.sakkinen@linux.intel.com/

exposure of the chip->tpm_mutex was removed from much of the upper
level code.  In this conversion, tpm2_del_space() was missed.  This
didn't matter much because it's usually called closely after a
converted operation, so there's only a very tiny race window where the
chip can be removed before the space flushing is done which causes a
NULL deref on the mutex.  However, there are reports of this window
being hit in practice, so fix this by converting tpm2_del_space() to
use tpm_try_get_ops(), which performs all the teardown checks before
acquring the mutex.

## Affected

- `linux_kernel >= 4.12, < 5.4.188`
- `linux_kernel >= 5.5, < 5.10.109`
- `linux_kernel >= 5.11, < 5.15.32`
- `linux_kernel >= 5.16, < 5.16.18`
- `linux_kernel = 5.17`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.16.18`
