CVE-2022-49476 is a Linux kernel vulnerability affecting the mt7921 Wi-Fi driver. It involves a kernel NULL pointer dereference that occurs during the removal of the mt7921 PCI device, leading to a system crash. The issue arises because the mt76 device is freed prematurely while the interrupt handler is still active. This vulnerability is rated as Medium severity (CVSS 5.5) with a local attack vector and low attack complexity. A successful exploit could lead to a denial of service (system crash), impacting system availability. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community attention, with no social media discussion or media coverage reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.12, < 5.17.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.18, < 5.18.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.