PT-2025-18645 · Linux+2 · Linux Kernel+2

Published

2022-10-20

·

Updated

2025-07-10

·

CVE-2022-49928

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A null pointer dereference issue has been identified in the Linux kernel's SUNRPC component. This issue occurs when the allocation of sysfs for xps fails, potentially leading to a null pointer dereference. The problem arises in the sysfs do create link sd function and is related to the rpc sysfs client setup and rpc new client functions. The estimated number of potentially affected devices is not provided.
Recommendations For Linux kernel versions prior to the fixed version, initialize the 'xps sysfs' to NULL to avoid errors when destroying it. When the xprt switch sysfs allocation fails, do not add xprt and switch sysfs to it to prevent potential null pointer dereferences. As a temporary workaround, consider disabling the sysfs do create link sd function until a patch is available. Restrict access to the vulnerable rpc sysfs client setup and rpc new client functions to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05783
CVE-2022-49928
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Affected Products

Astra Linux
Linux Kernel
Suse