PT-2025-18527 · Linux+2 · Linux Kernel+2

Published

2025-05-01

·

Updated

2026-05-26

·

CVE-2022-49810

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to missing xas retry() calls in xarray iteration within the netfslib module of the Linux kernel. This can cause a kernel NULL pointer dereference, leading to an error. The problem arises when the xarray walker returns a special value indicating that the walk needs to be redone from the root, but the necessary retry checks are not performed. This can result in an oops error, as shown in the provided stack trace. The error is caused by the lack of xas retry() calls in certain places within the netfslib module, which should be called at the beginning of the loop to check if the walk needs to be retried.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05811
CVE-2022-49810
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Affected Products

Astra Linux
Linux Kernel
Suse