suse · CVE-2026-22982

Quick triage

Priority: medium Published: 2026-03-05 00:18:08 UTC Updated: 2026-04-16 13:33:53 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-22982 severity moderate: SUSE including 380 source package names (13.2-9.1:libsqlite3-0-3.49.1-1.1, 2.1.3-6.124:kernel-default-base-6.4.0-40.1.21.17, …), 567 product×package rows across 61 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Container suse/sl-micro/6.0/base-os-container, … (61 product lines)): Fixed 246, Known Affected 231, Known Not Affected 65, First Fixed 25.

Description:

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix crash when adding interface under a lag Commit 15faa1f67ab4 ("lan966x: Fix crash when adding interface under a lag") fixed a similar issue in the lan966x driver caused by a NULL pointer dereference. The ocelot_set_aggr_pgids() function in the ocelot driver has similar logic and is susceptible to the same crash. This issue specifically affects the ocelot_vsc7514.c frontend, which leaves unused ports as NULL pointers. The felix_vsc9959.c frontend is unaffected as it uses the DSA framework which registers all ports. Fix this by checking if the port pointer is valid before accessing it.

cvelogic Threat Intelligence