CVE-2022-49448

In the Linux kernel, the following vulnerability has been resolved: soc: bcm: Check for NULL return of devm_kzalloc() As the potential failure of allocation, devm_kzalloc() may return NULL. Then the 'pd->pmb' and the follow lines of code may bring null pointer dereference. Therefore, it is better to check the return value of devm_kzalloc() to avoid this confusion.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

17 Mar 2025, 16:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux linux Kernel
Linux
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: soc: bcm: Verificar el retorno NULL de devm_kzalloc() Como posible fallo de asignación, devm_kzalloc() puede devolver NULL. Entonces, 'pd->pmb' y las siguientes líneas de código pueden generar una desreferencia de puntero nulo. Por lo tanto, es mejor verificar el valor de retorno de devm_kzalloc() para evitar esta confusión.
References () https://git.kernel.org/stable/c/36339ea7bae4943be01c8e9545e46e334591fecd - () https://git.kernel.org/stable/c/36339ea7bae4943be01c8e9545e46e334591fecd - Patch
References () https://git.kernel.org/stable/c/5650e103bfc70156001615861fb8aafb3947da6e - () https://git.kernel.org/stable/c/5650e103bfc70156001615861fb8aafb3947da6e - Patch
References () https://git.kernel.org/stable/c/b48b98743b568bb219152ba2e15af6ef0d3d8a9b - () https://git.kernel.org/stable/c/b48b98743b568bb219152ba2e15af6ef0d3d8a9b - Patch
References () https://git.kernel.org/stable/c/b4bd2aafacce48db26b0a213d849818d940556dd - () https://git.kernel.org/stable/c/b4bd2aafacce48db26b0a213d849818d940556dd - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-476

26 Feb 2025, 07:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:01

Updated : 2025-03-17 16:12


NVD link : CVE-2022-49448

Mitre link : CVE-2022-49448

CVE.ORG link : CVE-2022-49448


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference