PT-2025-8241 · Linux+2 · Linux Kernel+2
Zheyu Ma
·
Published
2022-04-14
·
Updated
2025-04-18
·
CVE-2022-49307
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A null-pointer-dereference issue in the
slgt clean() function of the synclink gt driver has been identified. This occurs when the driver fails at alloc hdlcdev() and the driver module is then removed, resulting in a general protection fault. The issue is caused by not checking if info->netdev is a null pointer before use.Recommendations
For the affected Linux kernel version, check whether
info->netdev is a null pointer before calling detach hdlc protocol() to prevent the null-pointer-dereference.
As a temporary workaround, consider disabling the slgt clean() function until a patch is available.Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse