U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-49806

Change History

New CVE Received from kernel.org 5/01/2025 11:16:03 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

net: microchip: sparx5: Fix potential null-ptr-deref in sparx_stats_init() and sparx5_start()

sparx_stats_init() calls create_singlethread_workqueue() and not
checked the ret value, which may return NULL. And a null-ptr-deref may
happen:

sparx_stats_init()
    create_singlethread_workqueue() # failed, sparx5->stats_queue is NULL
    queue_delayed_work()
        queue_delayed_work_on()
            __queue_delayed_work()  # warning here, but continue
                __queue_work()      # access wq->flags, null-ptr-deref

Check the ret value and return -ENOMEM if it is NULL. So as
sparx5_start().
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/456327e565dc49d18b2f595f39f47df8a36f1057
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/639f5d006e36bb303f525d9479448c412b720c39
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/80e590aeb132887102c3fa79d99b338f099dc952