CVE-2022-49423

Summary

In the Linux kernel, the following vulnerability has been resolved:

rtla: Avoid record NULL pointer dereference

Fix the following null/deref_null.cocci errors: ./tools/tracing/rtla/src/osnoise_hist.c:870:31-36: ERROR: record is NULL but dereferenced. ./tools/tracing/rtla/src/osnoise_top.c:650:31-36: ERROR: record is NULL but dereferenced. ./tools/tracing/rtla/src/timerlat_hist.c:905:31-36: ERROR: record is NULL but dereferenced. ./tools/tracing/rtla/src/timerlat_top.c:700:31-36: ERROR: record is NULL but dereferenced.

"record" is NULL before calling osnoise_init_trace_tool. Add a tag "out_free" to avoid dereferring a NULL pointer.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux51d64c3a181938da8fb56404524e15776e9c6bf8 < b0f1c686baff74d5df10f2f46670ef4e24a75756affected
LinuxLinux51d64c3a181938da8fb56404524e15776e9c6bf8 < 2a6b52ed72c822b5ee146a6a00ea66614fe02653affected
LinuxLinux5.18affected
LinuxLinux0 < 5.18unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

References