PT-2025-18582 · Linux+2 · Linux Kernel+2

Published

2022-11-07

·

Updated

2026-01-23

·

CVE-2022-49865

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, which was related to an information leak when sending a struct ifaddrlblmsg to the network. The issue occurred because the ifal reserved field remained uninitialized, resulting in a 1-byte infoleak. This problem was identified in the netdev start xmit function and was caused by the lack of initialization of the reserved field. The vulnerability was patched to ensure that the reserved field is always initialized.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05626
CVE-2022-49865
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Affected Products

Astra Linux
Linux Kernel
Suse