PT-2025-7979 · Linux+2 · Linux Kernel+2

Marcin Kozlowski

·

Published

2022-04-06

·

Updated

2025-04-16

·

CVE-2022-49051

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to out-of-bounds accesses in the aqc111 rx fixup() function, which can be triggered by a malicious or defective USB device. This can cause out-of-bounds reads and endianness flips on big-endian systems. Additionally, a packet can overlap the metadata array, leading to data corruption, or a packet SKB can be constructed with its tail beyond its end, causing out-of-bounds heap data to be considered part of the SKB's data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03653
CVE-2022-49051
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Suse