Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-49868— phy: ralink: mt7621-pci: add sentinel to quirks table

AI Predicted 5.5 Difficulty: Trivial EPSS 0.19% · P9

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinuxd87da32372a03ce121fc65ccd2c9a43edf56b364< 500bcd3a99eae84412067c3b9e7ffba1c66e6383affected
d87da32372a03ce121fc65ccd2c9a43edf56b364< d539cfd1202d66c2dcea383f1d96835ae72d5809affected
d87da32372a03ce121fc65ccd2c9a43edf56b364< 819b885cd886c193782891c4f51bbcab3de119a4affected
5.11affected
< 5.11unaffected
5.15.79≤ 5.15.*unaffected
6.0.9≤ 6.0.*unaffected
6.1≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-49868

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
phy: ralink: mt7621-pci: add sentinel to quirks table
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: phy: ralink: mt7621-pci: add sentinel to quirks table With mt7621 soc_dev_attr fixed to register the soc as a device, kernel will experience an oops in soc_device_match_attr This quirk test was introduced in the staging driver in commit 9445ccb3714c ("staging: mt7621-pci-phy: add quirks for 'E2' revision using 'soc_device_attribute'"). The staging driver was removed, and later re-added in commit d87da32372a0 ("phy: ralink: Add PHY driver for MT7621 PCIe PHY") for kernel 5.11
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于phy ralink驱动中mt7621-pci驱动缺少哨兵标记问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux d87da32372a03ce121fc65ccd2c9a43edf56b364 ~ 500bcd3a99eae84412067c3b9e7ffba1c66e6383 -
LinuxLinux 5.11 -

II. Public POCs for CVE-2022-49868

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-49868

登录查看更多情报信息。

Patches & Fixes for CVE-2022-49868 (3)

Same Patch Batch · Linux · 2025-05-01 · 245 CVEs total

CVE-2025-377509.8 CRITICALsmb: client: fix UAF in decryption with multichannel
CVE-2025-377768.8 HIGHksmbd: fix use-after-free in smb_break_all_levII_oplock()
CVE-2025-377778.8 HIGHksmbd: fix use-after-free in __smb2_lease_break_noti()
CVE-2025-231598.4 HIGHmedia: venus: hfi: add a check to handle OOB in sfr region
CVE-2025-377498.2 HIGHnet: ppp: Add bound checking for skb data on ppp_sync_txmung
CVE-2025-231417.8 HIGHKVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses
CVE-2025-377657.8 HIGHdrm/nouveau: prime: fix ttm_bo_delayed_delete oops
CVE-2025-377637.8 HIGHdrm/imagination: take paired job reference
CVE-2025-377567.8 HIGHnet: tls: explicitly disallow disconnect
CVE-2025-377527.8 HIGHnet_sched: sch_sfq: move the limit validation
CVE-2025-377797.8 HIGHlib/iov_iter: fix to increase non slab folio refcount
CVE-2025-377417.8 HIGHjfs: Prevent copying of nlink with value 0 from disk inode
CVE-2025-377387.8 HIGHext4: ignore xattrs past end
CVE-2025-231587.8 HIGHmedia: venus: hfi: add check to handle incorrect queue size
CVE-2025-231577.8 HIGHmedia: venus: hfi_parser: add check to avoid out of bound access
CVE-2025-231567.8 HIGHmedia: venus: hfi_parser: refactor hfi packet parsing logic
CVE-2025-231517.8 HIGHbus: mhi: host: Fix race between unprepare and queue_buf
CVE-2025-377897.8 HIGHnet: openvswitch: fix nested key length validation in the set() action
CVE-2025-231507.8 HIGHext4: fix off-by-one error in do_split
CVE-2025-231427.8 HIGHsctp: detect and prevent references to a freed transport in sendmsg

Showing top 20 of 245 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-49868

No comments yet


Leave a comment