PT-2024-8460 · Linux+3 · Linux Kernel+3

Jonathan Toppins

·

Published

2022-09-22

·

Updated

2025-09-18

·

CVE-2022-48640

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.0-rc4-00133-g64ae13ed4784
Description The vulnerability is related to a NULL dereference in the bond rr gen slave id function of the bonding driver. This occurs when a bond is initially created with an initial mode that is not zero (Round Robin), and the memory required for the counter is never created. When the mode is changed, there is no attempt to verify that the memory is allocated, resulting in a NULL dereference. This causes an Oops on an aarch64 machine.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the bond rr gen slave id function. Specifically, update to a version later than 6.0.0-rc4-00133-g64ae13ed4784.
As a temporary workaround, consider disabling the bond rr gen slave id function until a patch is available. However, this may have performance implications and should be carefully evaluated before implementation.
It is also recommended to restrict access to the bonding module to minimize the risk of exploitation until the issue is resolved.
Note: The provided information does not specify the exact version that includes the fix, so it is recommended to update to the latest available version of the Linux kernel.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10020
CVE-2022-48640
OPENSUSE-SU-2024_1644-1
OPENSUSE-SU-2024_1659-1
OPENSUSE-SU-2024_1663-1
SUSE-SU-2024:1644-1
SUSE-SU-2024:1659-1
SUSE-SU-2024:1663-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse