CVE-2022-49061: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: stmmac: fix altr_tse_pcs function when using a fixed-link When using a fixed-link, the altr_tse_pcs driver crashes due to null-pointer dereference as no phy_device is provided to tse_pcs_fix_mac_speed function. Fix this by adding a check for phy_dev before calling the tse_pcs_fix_mac_speed() function. Also clean up the tse_pcs_fix_mac_speed function a bit. There is no need to check for splitter_base and sgmii_adapter_base because the driver will fail if these 2 variables are not derived from the device tree.
Affected products
- Linux Linux Kernel: from 4.8, before 5.4.190 (fixed in 5.4.190); from 5.5, before 5.10.112 (fixed in 5.10.112); from 5.11, before 5.15.35 (fixed in 5.15.35); from 5.16, before 5.17.4 (fixed in 5.17.4); version 5.18 only
Published 2025-02-26. Last modified 2026-06-17.