PT-2025-25910 · Linux+3 · Linux Kernel+3

Published

2022-07-08

·

Updated

2025-07-28

·

CVE-2022-49984

CVSS v2.0

5.5

Medium

VectorAV:A/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference issue has been identified in the HID Steam driver of the Linux kernel. This issue arises when a malicious device fails to submit a Feature Report, and the driver attempts to access the struct hid report pointer without validating its existence. This could potentially lead to a crash or other unintended behavior.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02800
CVE-2022-49984
RHSA-2023:2458
RHSA-2023_2458
SUSE-SU-2025:02264-1
SUSE-SU-2025:02308-1
SUSE-SU-2025:02320-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02308-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse