CVE-2022-48843
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
16/07/2024
Last modified:
24/07/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/vrr: Set VRR capable prop only if it is attached to connector<br />
<br />
VRR capable property is not attached by default to the connector<br />
It is attached only if VRR is supported.<br />
So if the driver tries to call drm core set prop function without<br />
it being attached that causes NULL dereference.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.4.186 (excluding) | |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.107 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.30 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.16.16 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0ba557d330946c23559aaea2d51ea649fdeca98a
- https://git.kernel.org/stable/c/3534c5c005ef99a1804ed50b8a72cdae254cabb5
- https://git.kernel.org/stable/c/62929726ef0ec72cbbe9440c5d125d4278b99894
- https://git.kernel.org/stable/c/85271e92ae4f13aa679acaa6cf76b3c36bcb7bab
- https://git.kernel.org/stable/c/941e8bcd2b2ba95490738e33dfeca27168452779