cbcvebase.
CVE-2022-49664
published 2025-02-26

CVE-2022-49664: In the Linux kernel, the following vulnerability has been resolved: tipc: move bc link creation back to tipc_node_create Shuang Li reported a NULL pointer…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.68%
48.9th percentile
In the Linux kernel, the following vulnerability has been resolved: tipc: move bc link creation back to tipc_node_create Shuang Li reported a NULL pointer dereference crash: [] BUG: kernel NULL pointer dereference, address: 0000000000000068 [] RIP: 0010:tipc_link_is_up+0x5/0x10 [tipc] [] Call Trace: [] [] tipc_bcast_rcv+0xa2/0x190 [tipc] [] tipc_node_bc_rcv+0x8b/0x200 [tipc] [] tipc_rcv+0x3af/0x5b0 [tipc] [] tipc_udp_recv+0xc7/0x1e0 [tipc] It was caused by the 'l' passed into tipc_bcast_rcv() is NULL. When it creates a node in tipc_node_check_dest(), after inserting the new node into hashtable in tipc_node_create(), it creates the bc link. However, there is a gap between this insert and bc link creation, a bc packet may come in and get the node from the hashtable then try to dereference its bc link, which is NULL. This patch is to fix it by moving the bc link creation before inserting into the hashtable. Note that for a preliminary node becoming "real", the bc link creation should also be called before it's rehashed, as we don't create it for preliminary nodes.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 4cbf8ac2fe5a0846508fe02b95a5de1a90fa73f4 < 456bc338871c4a52117dd5ef29cce3745456d248456bc338871c4a52117dd5ef29cce3745456d248
linuxlinux>= 4cbf8ac2fe5a0846508fe02b95a5de1a90fa73f4 < 35fcb2ba35b4d9b592b558c3bcc6e0d90e21358835fcb2ba35b4d9b592b558c3bcc6e0d90e213588
linuxlinux>= 4cbf8ac2fe5a0846508fe02b95a5de1a90fa73f4 < e52910e671f58c619e33dac476b11b35e2d3ab6fe52910e671f58c619e33dac476b11b35e2d3ab6f
linuxlinux>= 4cbf8ac2fe5a0846508fe02b95a5de1a90fa73f4 < cb8092d70a6f5f01ec1490fce4d35efed3ed996ccb8092d70a6f5f01ec1490fce4d35efed3ed996c
linuxlinux>= 5.4.287 < 5.55.5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.11 < 5.15.535.15.53
linuxlinux_kernel>= 5.16 < 5.18.105.18.10
linuxlinux_kernel>= 5.4.287 < 5.10.1295.10.129

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.