vulnerability
Ubuntu: (CVE-2022-49806): linux vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | May 1, 2025 | May 8, 2025 | Apr 16, 2026 |
Description
In the Linux kernel, the following vulnerability has been resolved:
net: microchip: sparx5: Fix potential null-ptr-deref in sparx_stats_init() and sparx5_start()
sparx_stats_init() calls create_singlethread_workqueue() and not
checked the ret value, which may return NULL. And a null-ptr-deref may
happen:
sparx_stats_init()
create_singlethread_workqueue() # failed, sparx5->stats_queue is NULL
queue_delayed_work()
queue_delayed_work_on()
__queue_delayed_work() # warning here, but continue
__queue_work() # access wq->flags, null-ptr-deref
Check the ret value and return -ENOMEM if it is NULL. So as
sparx5_start().
Solutions
References
- CVE-2022-49806
- https://attackerkb.com/topics/CVE-2022-49806
- CWE-476
- EUVD-EUVD-2025-12976
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12976
- https://git.kernel.org/linus/639f5d006e36bb303f525d9479448c412b720c39
- https://git.kernel.org/stable/c/456327e565dc49d18b2f595f39f47df8a36f1057
- https://git.kernel.org/stable/c/639f5d006e36bb303f525d9479448c412b720c39
- https://git.kernel.org/stable/c/80e590aeb132887102c3fa79d99b338f099dc952
- https://www.cve.org/CVERecord?id=CVE-2022-49806
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.