PT-2025-8456 · Linux+2 · Linux Kernel+2

·

CVE-2022-49523

·

Published

2022-04-27

·

Updated

2026-08-15

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.10.120 Linux kernel versions prior to 5.15.45 Linux kernel versions prior to 5.17.13 Linux kernel versions prior to 5.18.2
Description A NULL pointer dereference exists in the ath11k spectral scan config() function within the drivers/net/wireless/ath/ath11k/spectral.c module of the Linux kernel. This issue occurs when ath11k modules are removed using rmmod while spectral scan is enabled, leading to a system crash and potential denial of service. The crash is triggered in the ath11k spectral process data() function during the spectral deinitialization process.
Recommendations Update the Linux kernel to version 5.10.120 or later. Update the Linux kernel to version 5.15.45 or later. Update the Linux kernel to version 5.17.13 or later. Update the Linux kernel to version 5.18.2 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02619
CVE-2022-49523
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Suse