PT-2025-8449 · Linux+3 · Linux Kernel+3

Published

2022-01-01

·

Updated

2026-05-26

·

CVE-2022-49516

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, where the ice get vf vsi function can return NULL in certain cases, such as during a reset where the VSI is being removed and recreated. The driver does not always check if the VSI pointer is valid, which can lead to potential issues. Static analysis tools may report problems due to the detection of paths where a potentially NULL pointer could be dereferenced.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2022-49516
SUSE-SU-2025:1176-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Debian
Linux Kernel
Suse