CVE-2022-49875

MEDIUM EPSS 7.3%
Published May 1, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 1, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: bpftool: Fix NULL pointer dereference when pin {PROG, MAP, LINK} without FILE When using bpftool to pin {PROG, MAP, LINK} without FILE, segmentation fault will occur. The reson is that the lack of FILE will cause strlen to trigger NULL pointer dereference. The corresponding stacktrace is shown below: do_pin do_pin_any do_pin_fd mount_bpffs_for_pin strlen(name) <- NULL pointer dereference Fix it by adding validation to the common process.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
7.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel*≥5.7  –  <5.10.155
linuxlinux_kernel*≥5.11  –  <5.15.79
linuxlinux_kernel*≥5.16  –  <6.0.9
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any

References 4

  • git.kernel.org https://git.kernel.org/stable/c/34de8e6e0e1f66e431abf4123934a2581cb5f133
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6dcdd1b68b7f9333d48d48fc77b75e7f235f6a4a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8c80b2fca4112d724dde477aed13f7b0510a2792
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/da5161ba94c5e9182c301dd4f09c94f715c068bd
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/34de8e6e0e1f66e431abf4123934a2581cb5f133
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6dcdd1b68b7f9333d48d48fc77b75e7f235f6a4a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8c80b2fca4112d724dde477aed13f7b0510a2792
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/da5161ba94c5e9182c301dd4f09c94f715c068bd
    Patch