PT-2025-18576 · Linux+1 · Linux Kernel+1

Published

2022-11-08

·

Updated

2025-05-02

·

CVE-2022-49859

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability has been resolved in the Linux kernel related to the lapbether module. The issue involves an invalid opcode in the lapbeth open() function. If lapb register() fails when the lapb device is started for the first time, NAPI is not disabled, resulting in the invalid opcode issue being reported when the lapb device is started for the second time. The stack trace indicates a kernel bug at net/core/dev.c:6442 and an invalid opcode at napi enable+0x16a/0x1f0. The call trace includes functions such as lapbeth open+0x18/0x90, dev open+0x258/0x490, and devinet ioctl+0x1276/0x1bf0.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-03977
CVE-2022-49859

Affected Products

Astra Linux
Linux Kernel