PT-2025-18542 · Linux+2 · Linux Kernel+2

Publicado

2022-11-08

·

Atualizado

2025-11-10

·

CVE-2022-49825

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.0-rc3+
Description A vulnerability in the Linux kernel has been resolved, specifically in the ata tport add() function. The return value of transport add device() is not checked, resulting in a null pointer dereference when removing the module. This occurs because transport remove device() is called to remove a device that was not added. The issue causes a kernel NULL pointer dereference at a virtual address.
Recommendations To resolve this issue, check and handle the return value of transport add device() in ata tport add(). As a temporary workaround, consider disabling the ata tport add() function until a patch is available. Restrict access to the libata module to minimize the risk of exploitation. Avoid using the transport add device() function in the affected kernel version until the issue is resolved.

Exploit

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05773
CVE-2022-49825
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:01982-1
SUSE-SU-2025:01995-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:02846-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_01982-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1
SUSE-SU-2025_02846-1

Produtos afetados

Astra Linux
Linux Kernel
Suse