CVE-2022-49131

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 26, 2025
Updated: Mar 13, 2025

Summary

CVE-2022-49130 is a vulnerability affecting the Linux kernel that specifically relates to the ath11k driver. The issue arises due to the use of the incorrect function mhi_async_power_up() instead of the safer mhi_sync_power_up() during the removal of the ath11k module, resulting in a general protection fault and potential crash. This error can be observed in the kernel log with a stack trace indicating a null pointer dereference. The cause for using the inappropriate function is unclear, but the synchronous version is considered safe in this context.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share