CVE-2022-49202

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
26/02/2025
Last modified:
22/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: hci_uart: add missing NULL check in h5_enqueue<br /> <br /> Syzbot hit general protection fault in __pm_runtime_resume(). The problem<br /> was in missing NULL check.<br /> <br /> hu-&gt;serdev can be NULL and we should not blindly pass &amp;serdev-&gt;dev<br /> somewhere, since it will cause GPF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15 (including) 5.15.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.16.19 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.17 (including) 5.17.2 (excluding)