We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-49805

net: lan966x: Fix potential null-ptr-deref in lan966x_stats_init()



Description

In the Linux kernel, the following vulnerability has been resolved: net: lan966x: Fix potential null-ptr-deref in lan966x_stats_init() lan966x_stats_init() calls create_singlethread_workqueue() and not checked the ret value, which may return NULL. And a null-ptr-deref may happen: lan966x_stats_init() create_singlethread_workqueue() # failed, lan966x->stats_queue is NULL queue_delayed_work() queue_delayed_work_on() __queue_delayed_work() # warning here, but continue __queue_work() # access wq->flags, null-ptr-deref Check the ret value and return -ENOMEM if it is NULL.

Reserved 2025-05-01 | Published 2025-05-01 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

12c2d0a5b8e2a1afc8c7738e19a0d1dd7f3d4007 before 4a43c1c6040e848e1344c7b16ac696b68fbc439c
affected

12c2d0a5b8e2a1afc8c7738e19a0d1dd7f3d4007 before ba86af3733aece88dbcee0dfebf7e2dcfefb2be4
affected

Default status
affected

5.17
affected

Any version before 5.17
unaffected

6.0.10
unaffected

6.1
unaffected

References

git.kernel.org/...c/4a43c1c6040e848e1344c7b16ac696b68fbc439c

git.kernel.org/...c/ba86af3733aece88dbcee0dfebf7e2dcfefb2be4

cve.org (CVE-2022-49805)

nvd.nist.gov (CVE-2022-49805)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2022-49805

Support options

Helpdesk Chat, Email, Knowledgebase