CVE-2022-49483

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/msm/disp/dpu1: avoid clearing hw interrupts if hw_intr is null during drm uninit

If edp modeset init is failed due to panel being not ready and probe defers during drm bind, avoid clearing irqs and dereference hw_intr when hw_intr is null.

BUG: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000

Call trace: dpu_core_irq_uninstall+0x50/0xb0 dpu_irq_uninstall+0x18/0x24 msm_drm_uninit+0xd8/0x16c msm_drm_bind+0x580/0x5fc try_to_bring_up_master+0x168/0x1c0 __component_add+0xb4/0x178 component_add+0x1c/0x28 dp_display_probe+0x38c/0x400 platform_probe+0xb0/0xd0 really_probe+0xcc/0x2c8 __driver_probe_device+0xbc/0xe8 driver_probe_device+0x48/0xf0 __device_attach_driver+0xa0/0xc8 bus_for_each_drv+0x8c/0xd8 __device_attach+0xc4/0x150 device_initial_probe+0x1c/0x28

Changes in V2:

  • Update commit message and coreect fixes tag.

Patchwork: https://patchwork.freedesktop.org/patch/484430/

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf25f656608e3a54ac3e0747be415cf3d4a69cef8 < a7ca30c3a8b2e8bda65f2b922d382ac056be8aa4affected
LinuxLinuxf25f656608e3a54ac3e0747be415cf3d4a69cef8 < a800701429313149afde18d98821554fbfcb3164affected
LinuxLinuxf25f656608e3a54ac3e0747be415cf3d4a69cef8 < 01013ba9bbddc62f7d011163cebfd7ed06bb698baffected
LinuxLinux5.16affected
LinuxLinux0 < 5.16unaffected
LinuxLinux5.17.14 <= 5.17.*unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References