PT-2025-8267 · Linux+4 · Linux Kernel+4

Published

2022-06-08

·

Updated

2026-05-26

·

CVE-2022-49333

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.18.0-rc7+
Description The issue is related to the Linux kernel, specifically with the mlx5 get next phys dev() function, which was called without holding the interface lock. This problem was identified when a commit added an assert that verifies the interface lock is held. The vulnerability is associated with the E-Switch and offloads pairing using devcom, which should only be possible on devices that support LAG.
Recommendations For Linux kernel versions prior to 5.18.0-rc7+, update to a version that includes the fix for the issue where mlx5 get next phys dev() was called without holding the interface lock. As a temporary workaround, consider disabling the mlx5 esw offloads devcom event() function until a patch is available. Restrict access to the vulnerable module mlx5 core to minimize the risk of exploitation. Avoid using the devcom parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
AZL-68618
BDU:2026-03673
CESA-2023_2951
CVE-2022-49333
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
SUSE-SU-2025:1176-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse