PT-2025-18582 · Linux+2 · Linux Kernel+2
Published
2022-11-07
·
Updated
2026-01-23
·
CVE-2022-49865
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved, which was related to an information leak when sending a
struct ifaddrlblmsg to the network. The issue occurred because the ifal reserved field remained uninitialized, resulting in a 1-byte infoleak. This problem was identified in the netdev start xmit function and was caused by the lack of initialization of the reserved field. The vulnerability was patched to ensure that the reserved field is always initialized.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Access of Uninitialized Pointer
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse