CVE-2022-49904 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net, neigh: Fix null-ptr-deref in neigh_table_clear() When IPv6 module gets initialized but hits an error in the middle, kenel panic with: KASAN: null-ptr-deref in range [0x0000000000000598-0x000000000000059f] CPU: 1 PID: 361 Comm: insmod Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) RIP: 0010:__neigh_ifdown.isra.0+0x24b/0x370 RSP: 0018:ffff888012677908 EFLAGS: 00000202 ... Call Trace: <TASK> neigh_table_clear+0x94/0x2d0 ndisc_cleanup+0x27/0x40 [ipv6] inet6_init+0x21c/0x2cb [ipv6] do_one_initcall+0xd3/0x4d0 do_init_module+0x1ae/0x670 ... Kernel panic - not syncing: Fatal exception When ipv6 initialization fails, it will try to cleanup and calls: neigh_table_clear() neigh_ifdown(tbl, NULL) pneigh_queue_purge(&tbl->proxy_queue, dev_net(dev == NULL)) # dev_net(NULL) triggers null-ptr-deref. Fix it by passing NULL to pneigh_queue_purge() in neigh_ifdown() if dev is NULL, to make kernel not panic immediately.
A null pointer dereference vulnerability has been identified in the Linux kernel's handling of IPv6 neighbor tables. This issue occurs in the 'neigh_table_clear()' function when the IPv6 module is initialized but encounters an error. The faulty cleanup process triggers a kernel panic by dereferencing a null pointer, causing a fatal exception and halting the system. The vulnerability arises because the 'ndisc_cleanup()' function, part of the IPv6 initialization process, calls 'neigh_table_clear()' without properly checking if the associated device is valid. As a result, the cleanup process attempts to purge the proxy queue of a non-existent device, leading to a crash.
The vulnerability has been addressed in the official Linux kernel repository. Users should upgrade to the latest version where this issue has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0d38b4ca6679e72860ff8730e79bb99d0e9fa3b0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1c89642e7f2b7ecc9635610653f5c2f0276c0051 | kernel.org | Patch |
| https://git.kernel.org/stable/c/2b45d6d0c41cb9593868e476681efb1aae5078a1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a99a8ec4c62180c889482a2ff6465033e0743458 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b49f6b2f21f543d4dc88fb7b1ec2adccb822f27c | kernel.org | Patch |
| https://git.kernel.org/stable/c/b736592de2aa53aee2d48d6b129bc0c892007bbe | kernel.org | Patch |
| https://git.kernel.org/stable/c/f8017317cb0b279b8ab98b0f3901a2e0ac880dad | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.14.292, < 4.14.299 >= 4.19.257, < 4.19.265 >= 5.4.212, < 5.4.224 >= 5.10.141, < 5.10.154 >= 5.15.65, < 5.15.78 >= 5.19.7, < 6.0.8 6.1 rc1 6.1 rc2 6.1 rc3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 1, 2025 | CVE Modified | CISA-ADP |
| May 7, 2025 | Initial Analysis | [email protected] |
| May 1, 2025 | New CVE Received | kernel.org |