PT-2025-25886 · Linux+4 · Linux Kernel+4

Published

2022-08-29

·

Updated

2025-07-28

·

CVE-2022-49960

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.0-rc1
Description A null pointer dereference issue has been identified in the Linux kernel, specifically in the tgl get bw info() function in drivers/gpu/drm/i915/display/intel bw.c. This issue causes a kernel panic and can lead to a crash during boot on affected devices, such as the Asus Chromebook CX550. The root cause is a null pointer dereference of bi next. Technical details about the issue include a null pointer dereference at address 000000000000002e and a call trace that includes functions like intel bw init hw() and i915 driver hw probe().
Recommendations For Linux kernel version 5.17.0-rc1, consider updating to a newer version to resolve the null pointer dereference issue. As a temporary workaround, consider disabling the tgl get bw info() function until a patch is available. Restrict access to the vulnerable module drivers/gpu/drm/i915/display/intel bw.c to minimize the risk of exploitation.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02060
CESA-2023_2951
CVE-2022-49960
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse