CVE-2022-48772
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
25/06/2024
Last modified:
03/09/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
media: lgdt3306a: Add a check against null-pointer-def<br />
<br />
The driver should check whether the client provides the platform_data.<br />
<br />
The following log reveals it:<br />
<br />
[ 29.610324] BUG: KASAN: null-ptr-deref in kmemdup+0x30/0x40<br />
[ 29.610730] Read of size 40 at addr 0000000000000000 by task bash/414<br />
[ 29.612820] Call Trace:<br />
[ 29.613030] <br />
[ 29.613201] dump_stack_lvl+0x56/0x6f<br />
[ 29.613496] ? kmemdup+0x30/0x40<br />
[ 29.613754] print_report.cold+0x494/0x6b7<br />
[ 29.614082] ? kmemdup+0x30/0x40<br />
[ 29.614340] kasan_report+0x8a/0x190<br />
[ 29.614628] ? kmemdup+0x30/0x40<br />
[ 29.614888] kasan_check_range+0x14d/0x1d0<br />
[ 29.615213] memcpy+0x20/0x60<br />
[ 29.615454] kmemdup+0x30/0x40<br />
[ 29.615700] lgdt3306a_probe+0x52/0x310<br />
[ 29.616339] i2c_device_probe+0x951/0xa90
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.4.278 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.219 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.161 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.94 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.34 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.9.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/526238d32c3acc3d597fd8c9a34652bfe9086cea
- https://git.kernel.org/stable/c/7d12e918f2994c883f41f22552a61b9310fa1e87
- https://git.kernel.org/stable/c/8915dcd29a82096acacf54364a8425363782aea0
- https://git.kernel.org/stable/c/8e1e00718d0d9dd83337300572561e30b9c0d115
- https://git.kernel.org/stable/c/b479fd59a1f4a342b69fce34f222d93bf791dca4
- https://git.kernel.org/stable/c/c1115ddbda9c930fba0fdd062e7a8873ebaf898d
- https://git.kernel.org/stable/c/d082757b8359201c3864323cea4b91ea30a1e676



