cbcvebase.
CVE-2022-49875
published 2025-05-01

CVE-2022-49875: In the Linux kernel, the following vulnerability has been resolved: bpftool: Fix NULL pointer dereference when pin {PROG, MAP, LINK} without FILE When using…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved: bpftool: Fix NULL pointer dereference when pin {PROG, MAP, LINK} without FILE When using bpftool to pin {PROG, MAP, LINK} without FILE, segmentation fault will occur. The reson is that the lack of FILE will cause strlen to trigger NULL pointer dereference. The corresponding stacktrace is shown below: do_pin do_pin_any do_pin_fd mount_bpffs_for_pin strlen(name) <- NULL pointer dereference Fix it by adding validation to the common process.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.10-1 (bookworm)linux 6.0.10-1 (bookworm)
linuxlinux
linuxlinux>= 75a1e792c335b5c6d7fdb1014da47aeb64c5944f < 8c80b2fca4112d724dde477aed13f7b0510a27928c80b2fca4112d724dde477aed13f7b0510a2792
linuxlinux>= 75a1e792c335b5c6d7fdb1014da47aeb64c5944f < 6dcdd1b68b7f9333d48d48fc77b75e7f235f6a4a6dcdd1b68b7f9333d48d48fc77b75e7f235f6a4a
linuxlinux>= 75a1e792c335b5c6d7fdb1014da47aeb64c5944f < da5161ba94c5e9182c301dd4f09c94f715c068bdda5161ba94c5e9182c301dd4f09c94f715c068bd
linuxlinux>= 75a1e792c335b5c6d7fdb1014da47aeb64c5944f < 34de8e6e0e1f66e431abf4123934a2581cb5f13334de8e6e0e1f66e431abf4123934a2581cb5f133
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 5.11 < 5.15.795.15.79
linuxlinux_kernel>= 5.16 < 6.0.96.0.9
linuxlinux_kernel>= 5.7 < 5.10.1555.10.155

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.