CVE-2022-49048: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix panic when forwarding a pkt with no in6 dev kongweibin reported a kernel panic in ip6_forward() when input interface has no in6 dev associated. The following tc commands were used to reproduce this panic: tc qdisc del dev vxlan100 root tc qdisc add dev vxlan100 root netem corrupt 5%
Affected products
- Linux Linux Kernel: from 4.19.199, before 4.19.239 (fixed in 4.19.239); from 5.4.136, before 5.4.190 (fixed in 5.4.190); from 5.10.54, before 5.10.112 (fixed in 5.10.112); from 5.13.6, before 5.14 (fixed in 5.14); from 5.14.1, before 5.15.35 (fixed in 5.15.35); from 5.16, before 5.17.4 (fixed in 5.17.4); …
Published 2025-02-26. Last modified 2026-08-04.