PT-2025-8176 · Linux+2 · Linux Kernel+2

Takashi Sakamoto

·

Published

2022-03-04

·

Updated

2025-06-17

·

CVE-2022-49248

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the version that includes the fix for the uninitialized flag for AV/C deferred transaction
Description The issue is related to an uninitialized flag for AV/C deferred transactions in the Linux kernel. The problem was introduced when support for deferred transactions was added. The UBSAN reports an invalid load due to the uninitialized deferrable flag for non-control/notify AV/C transactions. The bug does not affect non-control/notify AV/C transactions since the flag only affects AV/C responses with an INTERIM status, which is not used in the AV/C general specification.
Recommendations For Linux kernel versions prior to the fixed version, consider applying the patch that fixes the uninitialized flag for AV/C deferred transactions to resolve the issue. As a temporary workaround, there is no specific recommendation provided, but ensuring that the kernel is updated to the latest version when available would be a general best practice. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04315
CVE-2022-49248
OESA-2025-1317
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Astra Linux
Linux Kernel
Suse