PT-2025-8263 · Linux+3 · Linux Kernel+3

Oliver Sang

·

Published

2024-11-12

·

Updated

2025-09-29

·

CVE-2022-49329

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference issue has been identified in the Linux kernel, specifically in the vduse component when accessing the control device's msg timeout attribute via sysfs. This issue occurs because the control device lacks drvdata, leading to a NULL pointer dereference. The problem is evident when the msg timeout show function is called, resulting in a kernel NULL pointer dereference error.
Recommendations To resolve this issue, do not create the unneeded attribute for the control device anymore, as this attribute is the cause of the NULL pointer dereference.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
CVE-2022-49329
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2025:1176-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse