PT-2025-8488 · Linux+2 · Linux Kernel+2
Steven Rostedt
·
Published
2022-05-13
·
Updated
2025-04-16
·
CVE-2022-49555
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved. The issue is related to the hci qca driver, where a timer is freed while still active, commonly triggered by calling del timer() instead of del timer sync() before freeing. This can cause a crash report due to a corrupted timer list. The hci qca driver is the possible culprit, and the wake retrans timer can be rearmed via the work queue.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse