VYPR
High severity7.5NVD Advisory· Published Jun 18, 2025· Updated Aug 4, 2026

CVE-2022-49997

CVE-2022-49997

Description

In the Linux kernel, the following vulnerability has been resolved:

net: lantiq_xrx200: restore buffer if memory allocation failed

In a situation where memory allocation fails, an invalid buffer address is stored. When this descriptor is used again, the system panics in the build_skb() function when accessing memory.

Affected products

8
  • Linux/Kernel7 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.4.128,<5.5
    • cpe:2.3:o:linux:linux_kernel:5.13:-:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:5.13:rc7:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 5.13
  • osv-coords
    Range: >= 5.13.0, < 5.19.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.