PT-2025-8423 · Linux+2 · Linux Kernel+2

Tomeu Vizoso

·

Published

2022-05-06

·

Updated

2025-04-15

·

CVE-2022-49490

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, where the mdp5 pipe release function does not check for errors returned by mdp5 get global state, potentially leading to a NULL dereference error. This issue arises when mdp5 get global state attempts to acquire the modeset lock and encounters a deadlock, resulting in a -EDEADLK error. To mitigate this, the mdp5 pipe release function has been modified to propagate any errors returned by mdp5 get global state.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04026
CVE-2022-49490
OESA-2025-1336
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:0834-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_0834-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Astra Linux
Linux Kernel
Suse