PT-2025-8027 · Linux+2 · Linux Kernel+2

Published

2022-03-29

·

Updated

2025-04-14

·

CVE-2022-49099

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17-rc7
Description A vulnerability in the Linux kernel has been resolved. The issue was related to the initialization of device objects in the vmbus device register() function. The device's dma mask and dma parms pointers, as well as the device's dma mask value, were not properly initialized before invoking device register(). This led to a warning trace being generated.
Recommendations For Linux kernel versions prior to 5.17-rc7, update to version 5.17-rc7 or later to resolve the issue. As a temporary workaround, consider disabling the vmbus device register() function until a patch is available. Restrict access to the hv vmbus module to minimize the risk of exploitation. Avoid using the dma mask and dma parms variables in the affected code until the issue is resolved.

Exploit

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04071
CVE-2022-49099
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Suse