CVE-2022-49453

Summary

In the Linux kernel, the following vulnerability has been resolved:

soc: ti: ti_sci_pm_domains: Check for null return of devm_kcalloc

The allocation funciton devm_kcalloc may fail and return a null pointer, which would cause a null-pointer dereference later. It might be better to check it and directly return -ENOMEM just like the usage of devm_kcalloc in previous code.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxefa5c01cd7ee20421a92ffe9b4aae7dfed385eeb < 05efc4591f80582b6fe53366b70b6a35a42fd255affected
LinuxLinuxefa5c01cd7ee20421a92ffe9b4aae7dfed385eeb < 7cef9274fa1b8506949d74bc45aef072b890824aaffected
LinuxLinuxefa5c01cd7ee20421a92ffe9b4aae7dfed385eeb < c4e188869406b47ac3350920bf165be303cb1c96affected
LinuxLinuxefa5c01cd7ee20421a92ffe9b4aae7dfed385eeb < 01ba41a359622ab256ce4d4f8b94c67165ae3dafaffected
LinuxLinuxefa5c01cd7ee20421a92ffe9b4aae7dfed385eeb < ba56291e297d28aa6eb82c5c1964fae2d7594746affected
LinuxLinux5.10affected
LinuxLinux0 < 5.10unaffected
LinuxLinux5.10.121 <= 5.10.*unaffected
LinuxLinux5.15.46 <= 5.15.*unaffected
LinuxLinux5.17.14 <= 5.17.*unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References