PT-2025-25884 · Linux+4 · Linux Kernel+4

Published

2022-08-30

·

Updated

2025-07-28

·

CVE-2022-49958

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, which was related to netdevice reference leaks in the attach default qdiscs() function. If a device has multiple queues and queue 0 fails to attach a qdisc due to memory issues, the device's qdisc will default to noop qdisc. However, other queues may still successfully attach to the default qdisc, triggering a fallback to the noqueue process. If the original attached qdisc is not released and a new one is directly attached, this will cause netdevice reference leaks.
Recommendations To fix this bug, clear any non-noop qdiscs that may have been assigned before trying to re-attach. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02022
CESA-2023_2951
CVE-2022-49958
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse