PT-2025-18585 · Linux+2 · Linux Kernel+2

Published

2025-05-01

·

Updated

2025-07-10

·

CVE-2022-49868

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.11
Description A vulnerability has been resolved in the Linux kernel. The issue is related to the phy: ralink: mt7621-pci driver, where a sentinel was added to the quirks table. With the correction of the mt7621 soc dev attr variable to register the SOC as a device, the kernel would experience an error in soc device match attr. This quirk test was introduced in the staging driver and later removed and re-added for kernel 5.11.
Recommendations For Linux kernel versions prior to 5.11, update to kernel version 5.11 or later to resolve the issue. As a temporary workaround, consider disabling the soc device match attr function until a patch is available. Restrict access to the mt7621-pci-phy driver to minimize the risk of exploitation. Avoid using the soc dev attr variable in the affected driver until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-49868
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Affected Products

Astra Linux
Linux Kernel
Suse