PT-2025-8465 · Linux+2 · Linux Kernel+2

Published

2022-03-25

·

Updated

2025-04-16

·

CVE-2022-49532

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A NULL pointer dereference vulnerability has been found in the Linux kernel, specifically in the virtio gpu conn get modes function. This issue occurs because drm cvt mode may return NULL, and the code does not check for this condition. The vulnerability was discovered using the syzkaller tool. Technical details about the issue include a null-ptr-deref in virtio gpu conn get modes+0xb4/0x140 due to a read of size 4 at addr 0000000000000054.
Recommendations As a temporary workaround, consider disabling the virtio gpu module until a patch is available. Restrict access to the drm ioctl and drm mode getconnector functions to minimize the risk of exploitation. Avoid using the virtio gpu conn get modes function until the issue is resolved. Update to a newer version of the Linux kernel that includes the fix for this issue.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02620
CVE-2022-49532
OESA-2025-1317
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Suse