PT-2026-4482 · Linux+4 · Linux Kernel+4

Published

2026-01-01

·

Updated

2026-06-04

·

CVE-2026-22982

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel's ocelot driver, specifically within the ocelot set aggr pgids() function. This issue can lead to a crash when adding an interface under a link aggregation (lag). The problem stems from a potential NULL pointer dereference in the ocelot vsc7514.c frontend, where unused ports may not be properly initialized. The felix vsc9959.c frontend is not affected because it utilizes the DSA framework, which ensures all ports are registered. The root cause was identified and addressed in a previous fix for the lan966x driver (commit 15faa1f67ab4).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-78461
BDU:2026-04918
CVE-2026-22982
ECHO-BB11-F525-FF6A
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8243-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2
USN-8393-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
Lan966X
Ocelot