PT-2025-18576 · Linux+1 · Linux Kernel+1
Published
2022-11-08
·
Updated
2025-05-02
·
CVE-2022-49859
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability has been resolved in the Linux kernel related to the lapbether module. The issue involves an invalid opcode in the
lapbeth open() function. If lapb register() fails when the lapb device is started for the first time, NAPI is not disabled, resulting in the invalid opcode issue being reported when the lapb device is started for the second time. The stack trace indicates a kernel bug at net/core/dev.c:6442 and an invalid opcode at napi enable+0x16a/0x1f0. The call trace includes functions such as lapbeth open+0x18/0x90, dev open+0x258/0x490, and devinet ioctl+0x1276/0x1bf0.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel