CVE-2022-49859
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2022-49859 is a vulnerability in the Linux kernel's LAPB (Link Access Procedure Balanced) Ethernet implementation. The issue was discovered and disclosed on May 1, 2025. The vulnerability affects the net/lapbether subsystem, specifically in the lapbeth_open() function. This vulnerability impacts various Linux kernel versions, particularly affecting systems running Ubuntu 22.04 LTS and related distributions (Ubuntu Security, NVD).

Technical details

The vulnerability occurs when lapb_register() fails during the first attempt to bring up a LAPB device. In this scenario, the NAPI (New API) is not properly disabled, leading to an invalid opcode issue when the device attempts to go up for the second time. The issue manifests as a kernel BUG at net/core/dev.c:6442 with an invalid opcode: 0000 [#1] PREEMPT SMP KASAN error. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 with attack vector metrics of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat Security).

Impact

The vulnerability can lead to system instability and potential denial of service conditions when attempting to bring up LAPB devices. The CVSS metrics indicate that while the vulnerability requires local access and low privileges, it can result in high availability impact to the affected system (Red Hat Security).

Mitigation and workarounds

Multiple Linux distributions have released patches to address this vulnerability. Ubuntu has fixed the issue in version 5.15.0-67.74 for Ubuntu 22.04 LTS and related kernel versions. Various other Ubuntu kernels including linux-aws (5.15.0-1031.35), linux-azure (5.15.0-1034.41), and linux-gke (5.15.0-1028.33) have also received patches (Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11266MEDIUM6.8
  • Linux DebianLinux Debian
  • gdcm
NoNoDec 12, 2025
CVE-2025-67897MEDIUM5.3
  • Linux DebianLinux Debian
  • rust-sequoia-openpgp
NoYesDec 14, 2025
CVE-2025-14607MEDIUM5.3
  • Linux DebianLinux Debian
  • dcmtk
NoNoDec 13, 2025
CVE-2025-67749MEDIUM5.3
  • Linux DebianLinux Debian
  • pcsx2
NoNoDec 12, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management