CVE-2022-49448

Summary

In the Linux kernel, the following vulnerability has been resolved:

soc: bcm: Check for NULL return of devm_kzalloc()

As the potential failure of allocation, devm_kzalloc() may return NULL. Then the 'pd->pmb' and the follow lines of code may bring null pointer dereference.

Therefore, it is better to check the return value of devm_kzalloc() to avoid this confusion.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux8bcac4011ebe0dbdd46fd55b036ee855c95702d3 < 5650e103bfc70156001615861fb8aafb3947da6eaffected
LinuxLinux8bcac4011ebe0dbdd46fd55b036ee855c95702d3 < 36339ea7bae4943be01c8e9545e46e334591fecdaffected
LinuxLinux8bcac4011ebe0dbdd46fd55b036ee855c95702d3 < b48b98743b568bb219152ba2e15af6ef0d3d8a9baffected
LinuxLinux8bcac4011ebe0dbdd46fd55b036ee855c95702d3 < b4bd2aafacce48db26b0a213d849818d940556ddaffected
LinuxLinux5.12affected
LinuxLinux0 < 5.12unaffected
LinuxLinux5.15.46 <= 5.15.*unaffected
LinuxLinux5.17.14 <= 5.17.*unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References