PT-2022-7460 · Linux+4 · Linux Kernel+4

Published

2022-02-18

·

Updated

2024-09-26

·

CVE-2022-48850

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel's net-sysfs component can cause a panic when bringing down a network device or during system shutdown. This occurs because the device is already removed when the sysfs path is accessed. The issue is related to the speed show function, which does not check if the network device is present before accessing it. This can lead to a NULL pointer dereference, resulting in a kernel panic. The vulnerability is triggered when the mlx5 core driver is used, and the dma pool alloc function is called. The cmd exec, mlx5 cmd exec, mlx5 core access reg, mlx5e get fec caps, get fec supported advertised, mlx5e get link ksettings, and ethtool get link ksettings functions are also involved in the vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06531
CVE-2022-48850
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1
USN-7039-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse
Ubuntu