cbcvebase.
CVE-2022-48972
published 2024-10-21

CVE-2022-48972: In the Linux kernel, the following vulnerability has been resolved: mac802154: fix missing INIT_LIST_HEAD in ieee802154_if_add() Kernel fault injection test…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.3th percentile
In the Linux kernel, the following vulnerability has been resolved: mac802154: fix missing INIT_LIST_HEAD in ieee802154_if_add() Kernel fault injection test reports null-ptr-deref as follows: BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:cfg802154_netdev_notifier_call+0x120/0x310 include/linux/list.h:114 Call Trace: raw_notifier_call_chain+0x6d/0xa0 kernel/notifier.c:87 call_netdevice_notifiers_info+0x6e/0xc0 net/core/dev.c:1944 unregister_netdevice_many_notify+0x60d/0xcb0 net/core/dev.c:1982 unregister_netdevice_queue+0x154/0x1a0 net/core/dev.c:10879 register_netdevice+0x9a8/0xb90 net/core/dev.c:10083 ieee802154_if_add+0x6ed/0x7e0 net/mac802154/iface.c:659 ieee802154_register_hw+0x29c/0x330 net/mac802154/main.c:229 mcr20a_probe+0xaaa/0xcb1 drivers/net/ieee802154/mcr20a.c:1316 ieee802154_if_add() allocates wpan_dev as netdev's private data, but not init the list in struct wpan_dev. cfg802154_netdev_notifier_call() manage the list when device register/unregister, and may lead to null-ptr-deref. Use INIT_LIST_HEAD() on it to initialize it correctly.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= fcf39e6e88e9492f6688ec8ba4e1be622b904232 < 7410f4d1221bb182510b7778ab6eefa8b9b7102d7410f4d1221bb182510b7778ab6eefa8b9b7102d
linuxlinux>= fcf39e6e88e9492f6688ec8ba4e1be622b904232 < 9980a3ea20de40c83817877106c909cb032692d29980a3ea20de40c83817877106c909cb032692d2
linuxlinux>= fcf39e6e88e9492f6688ec8ba4e1be622b904232 < f00c84fb1635c27ba24ec5df65d5bd7d7dc00008f00c84fb1635c27ba24ec5df65d5bd7d7dc00008
linuxlinux>= fcf39e6e88e9492f6688ec8ba4e1be622b904232 < 1831d4540406708e48239cf38fd9c3b7ea98e08f1831d4540406708e48239cf38fd9c3b7ea98e08f
linuxlinux>= fcf39e6e88e9492f6688ec8ba4e1be622b904232 < 42c319635c0cf7eb36eccac6cda76532f47b61a342c319635c0cf7eb36eccac6cda76532f47b61a3
linuxlinux>= fcf39e6e88e9492f6688ec8ba4e1be622b904232 < a110287ef4a423980309490df632e1c1e73b3dc9a110287ef4a423980309490df632e1c1e73b3dc9
linuxlinux>= fcf39e6e88e9492f6688ec8ba4e1be622b904232 < 623918f40fa68e3bb21312a3fafb90f491bf5358623918f40fa68e3bb21312a3fafb90f491bf5358
linuxlinux>= fcf39e6e88e9492f6688ec8ba4e1be622b904232 < b3d72d3135d2ef68296c1ee174436efd65386f04b3d72d3135d2ef68296c1ee174436efd65386f04
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 3.19 < 4.9.3364.9.336
linuxlinux_kernel>= 4.10 < 4.14.3024.14.302
linuxlinux_kernel>= 4.15 < 4.19.2694.19.269
linuxlinux_kernel>= 4.20 < 5.4.2275.4.227
linuxlinux_kernel>= 5.11 < 5.15.835.15.83
linuxlinux_kernel>= 5.16 < 6.0.136.0.13
linuxlinux_kernel>= 5.5 < 5.10.1595.10.159

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.