PT-2025-7979 · Linux+2 · Linux Kernel+2

·

CVE-2022-49051

·

Published

2022-04-06

·

Updated

2026-08-13

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The aqc111 rx fixup() function in the Linux kernel contains multiple out-of-bounds accesses that can be triggered by a defective or malicious USB device. These issues include the metadata array potentially being out of bounds, leading to out-of-bounds reads and endianness flips on big-endian systems. Additionally, a packet may overlap the metadata array, causing subsequent endianness flips to corrupt data in a cloned SKB (Socket Buffer) already processed by the network stack. Furthermore, a packet SKB can be created with a tail extending far beyond its end, resulting in out-of-bounds heap data being treated as part of the SKB data. This can impact the confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03653
CVE-2022-49051
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Suse