PT-2025-8487 · Linux+1 · Linux Kernel+1

Sultan Alsawaf

·

Published

2022-05-13

·

Updated

2025-02-27

·

CVE-2022-49554

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A issue in the Linux kernel has been identified, where the asynchronous zspage free worker does not properly defend against page migration, leading to potential races. This can cause the worker to lock a page that no longer belongs to the zspage, unsafely dereference page private(), or observe a spurious NULL pointer to the next page. The issue is resolved by using migrate read lock() in lock zspage() to synchronize with page migration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2026-04021
CVE-2022-49554

Affected Products

Astra Linux
Linux Kernel