CVE-2022-49090 is a NULL pointer dereference vulnerability in the Linux kernel's core scheduling topology initialization for Arm64 systems. This flaw can lead to a system crash (denial of service) if core scheduling is enabled, particularly when using tools like stress-ng. Rated as Medium severity (CVSS 5.5), the vulnerability requires local access and low privileges to exploit, with no user interaction needed. The impact is primarily system availability, as it can cause a kernel panic. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.14, < 5.15.34CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.16.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.17, < 5.17.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.18:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.