PT-2025-8079 · Linux+2 · Linux Kernel+2

·

CVE-2022-49151

·

Published

2022-03-31

·

Updated

2025-04-15

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.0-rc6-syzkaller-00184-g38f80f42147f
Description A warning in usb submit urb() was reported by Syzbot due to a wrong endpoint type. The issue occurs because the endpoint type is not properly checked. To prevent this warning, the code now checks if the in endpoint is actually present and saves found pipes to struct mcba priv, using them directly instead of making pipes in place.
Recommendations For Linux kernel versions prior to 5.17.0-rc6-syzkaller-00184-g38f80f42147f, update to a newer version that includes the fix for the mcba usb module to properly check endpoint types and prevent warnings in usb submit urb().

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12370
CVE-2022-49151
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:0834-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_0834-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Astra Linux
Linux Kernel
Suse