In the Linux kernel, the following vulnerability has been resolved:
clk: Fix clk_hw_get_clk() when dev is NULL
Any registered clk_core structure can have a NULL pointer in its dev
field. While never actually documented, this is evidenced by the wide
usage of clk_register and clk_hw_register with a NULL device pointer,
and the fact that the core of_clk_hw_register() function also passes a
NULL device pointer.
A call to clk_hw_get_clk() on a clk_hw struct whose clk_core is in that
case will result in a NULL pointer derefence when it calls dev_name() on
that NULL device pointer.
Add a test for this case and use NULL as the dev_id if the device
pointer is NULL.
References
Configurations
Configuration 1 (hide)
|
History
14 Mar 2025, 20:57
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
First Time |
Linux linux Kernel
Linux |
|
References | () https://git.kernel.org/stable/c/0c1b56df451716ba207bbf59f303473643eee4fd - Patch | |
References | () https://git.kernel.org/stable/c/23f89fe005b105f0dcc55034c13eb89f9b570fac - Patch | |
References | () https://git.kernel.org/stable/c/4be3e4c05d8dd1b83b75652cad88c9e752ec7054 - Patch | |
References | () https://git.kernel.org/stable/c/d183f20cf5a7b546d4108e796b98210ceb317579 - Patch | |
Summary |
|
|
CWE | CWE-476 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
26 Feb 2025, 07:00
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-26 07:00
Updated : 2025-03-14 20:57
NVD link : CVE-2022-49187
Mitre link : CVE-2022-49187
CVE.ORG link : CVE-2022-49187
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-476
NULL Pointer Dereference