In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands. This affects qdiscgraft in net/sched/schapi.c.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-47929.json"
[
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@96398560f26aa07e8f2969d73c8197e6a6d10407",
"digest": {
"line_hashes": [
"288169544233175079284627455935262842388",
"335584521426481267141852452762523560082",
"154377560542810250669631777362242880387"
],
"threshold": 0.9
},
"id": "CVE-2022-47929-9884489a",
"deprecated": false,
"target": {
"file": "net/sched/sch_api.c"
}
}
]