PT-2025-25915 · Linux+2 · Linux Kernel+2

Published

2022-08-25

·

Updated

2025-07-28

·

CVE-2022-49989

CVSS v2.0

5.5

Medium

VectorAV:A/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the error exit of privcmd ioctl dm op() in the Linux kernel, specifically in the xen/privcmd module. This error exit potentially calls unlock pages() with pages being NULL, leading to a NULL dereference. Additionally, lock pages() does not check if pin user pages fast() has been completely successful, which may result in not locking all pages into memory. This could cause sporadic failures when using the related memory in user mode.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02801
CVE-2022-49989
OESA-2025-1820
SUSE-SU-2025:02264-1
SUSE-SU-2025:02308-1
SUSE-SU-2025:02320-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02308-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Linux Kernel
Suse