cbcvebase.
CVE-2022-49262
published 2025-02-26

CVE-2022-49262: In the Linux kernel, the following vulnerability has been resolved: crypto: octeontx2 - remove CONFIG_DM_CRYPT check No issues were found while using the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: octeontx2 - remove CONFIG_DM_CRYPT check No issues were found while using the driver with dm-crypt enabled. So CONFIG_DM_CRYPT check in the driver can be removed. This also fixes the NULL pointer dereference in driver release if CONFIG_DM_CRYPT is enabled. ... Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 ... Call trace: crypto_unregister_alg+0x68/0xfc crypto_unregister_skciphers+0x44/0x60 otx2_cpt_crypto_exit+0x100/0x1a0 otx2_cptvf_remove+0xf8/0x200 pci_device_remove+0x3c/0xd4 __device_release_driver+0x188/0x234 device_release_driver+0x2c/0x4c ...

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 6f03f0e8b6c8a82d8e740ff3a87ed407ad423243 < e6374086f249295121384bfaa7cdcc8d461146f0e6374086f249295121384bfaa7cdcc8d461146f0
linuxlinux>= 6f03f0e8b6c8a82d8e740ff3a87ed407ad423243 < a462214866eebbca87e13ff6d73092b1c4895624a462214866eebbca87e13ff6d73092b1c4895624
linuxlinux>= 6f03f0e8b6c8a82d8e740ff3a87ed407ad423243 < a1bf728f3388ac3a2c2dffa57e25622e90b9f6f2a1bf728f3388ac3a2c2dffa57e25622e90b9f6f2
linuxlinux>= 6f03f0e8b6c8a82d8e740ff3a87ed407ad423243 < 2d841af23ae8f398c85dd1ff2dc24b5ec8ba45692d841af23ae8f398c85dd1ff2dc24b5ec8ba4569
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.12 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.