CVE-2022-49848

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
01/05/2025
Last modified:
01/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> phy: qcom-qmp-combo: fix NULL-deref on runtime resume<br /> <br /> Commit fc64623637da ("phy: qcom-qmp-combo,usb: add support for separate<br /> PCS_USB region") started treating the PCS_USB registers as potentially<br /> separate from the PCS registers but used the wrong base when no PCS_USB<br /> offset has been provided.<br /> <br /> Fix the PCS_USB base used at runtime resume to prevent dereferencing a<br /> NULL pointer on platforms that do not provide a PCS_USB offset (e.g.<br /> SC7180).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.0 (including) 6.0.9 (excluding)
cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:rc4:*:*:*:*:*:*