PT-2025-18585 · Linux+2 · Linux Kernel+2
Published
2025-05-01
·
Updated
2025-07-10
·
CVE-2022-49868
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.11
Description
A vulnerability has been resolved in the Linux kernel. The issue is related to the phy: ralink: mt7621-pci driver, where a sentinel was added to the quirks table. With the correction of the
mt7621 soc dev attr variable to register the SOC as a device, the kernel would experience an error in soc device match attr. This quirk test was introduced in the staging driver and later removed and re-added for kernel 5.11.Recommendations
For Linux kernel versions prior to 5.11, update to kernel version 5.11 or later to resolve the issue. As a temporary workaround, consider disabling the
soc device match attr function until a patch is available. Restrict access to the mt7621-pci-phy driver to minimize the risk of exploitation. Avoid using the soc dev attr variable in the affected driver until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse