SB20250226462 - NULL pointer dereference in Linux kernel ethernet ibm driver
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2022-49201)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the __ibmvnic_open(), ibmvnic_cleanup(), ibmvnic_tx_scrq_clean_buffer(), ibmvnic_xmit() and netif_carrier_off() functions in drivers/net/ethernet/ibm/ibmvnic.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1bd58abf595b6cf1ba6dd47ec887c4c009155fc9
- https://git.kernel.org/stable/c/4219196d1f662cb10a462eb9e076633a3fc31a15
- https://git.kernel.org/stable/c/475f9cce98b63bc145b4efa66fa51175d4cb345f
- https://git.kernel.org/stable/c/8507c6ade73cdbbbda5c3d31d67f52f2e1cf03fe
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.2