PT-2022-7460 · Linux+4 · Linux Kernel+4
Published
2022-02-18
·
Updated
2024-09-26
·
CVE-2022-48850
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel's net-sysfs component can cause a panic when bringing down a network device or during system shutdown. This occurs because the device is already removed when the sysfs path is accessed. The issue is related to the
speed show function, which does not check if the network device is present before accessing it. This can lead to a NULL pointer dereference, resulting in a kernel panic. The vulnerability is triggered when the mlx5 core driver is used, and the dma pool alloc function is called. The cmd exec, mlx5 cmd exec, mlx5 core access reg, mlx5e get fec caps, get fec supported advertised, mlx5e get link ksettings, and ethtool get link ksettings functions are also involved in the vulnerability.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse
Ubuntu