PT-2024-10523 · Linux+3 · Linux Kernel+3

Abdul Haleem

·

Published

2022-02-08

·

Updated

2026-03-14

·

CVE-2022-48811

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.16.0-rc5-autotest-g6441998e2e37
Description The vulnerability is related to the ibmvnic component in the Linux kernel. When the ibmvnic open() function encounters an error, such as when setting link state, it calls release resources() which frees the napi structures needlessly. This can lead to a crash when running the drmgr command several times to add/remove a vnic interface. The issue is caused by a NULL pointer dereference on read at address 0x00000010. The vulnerability can be exploited by an attacker to cause a denial of service.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the ibmvnic component. Specifically, update to a version later than 5.16.0-rc5-autotest-g6441998e2e37. As a temporary workaround, consider disabling the ibmvnic open() function until a patch is available. Restrict access to the vulnerable ibmvnic component to minimize the risk of exploitation. Avoid using the drmgr command to add/remove vnic interfaces until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01074
CVE-2022-48811
OESA-2024-2106
OESA-2024-2107
OESA-2024-2108
OPENSUSE-SU-2024_2947-1
OPENSUSE-SU-2024_3249-1
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:3225-1
SUSE-SU-2024:3249-1

Affected Products

Debian
Linux Kernel
Red Os
Suse