CVE-2022-48812
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a vulnerability has been identified and resolved in the net: dsa: lantiqgswip component. The issue involves improper handling of mdiobus allocation and registration, which could lead to a kernel panic when mdiobusfree() is called from devmmdiobusfree() during device driver release. This vulnerability was discovered and fixed in 2022 (Kernel Commit).

Technical details

The vulnerability occurs when the DSA master is on a bus that calls ->remove from ->shutdown (like dpaa2-eth on the fsl-mc bus). In this scenario, a device link exists between the switch and the DSA master, and devicelinksunbindconsumers() will unbind the GSWIP switch driver on shutdown. The issue specifically manifests when mdiobusfree() is called from devmmdiobusfree() <- devresreleaseall() <- _devicerelease_driver(), and the mdiobus was not previously unregistered (Kernel Commit).

Impact

When triggered, this vulnerability can cause a kernel panic, potentially leading to system instability or denial of service conditions (Kernel Commit).

Mitigation and workarounds

The issue has been fixed by replacing devmmdiobusalloc() with the non-devres variant and adding manual free operations where necessary. The fix ensures proper handling of mdiobus allocation and deallocation, preventing the kernel panic condition (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management