CVE-2022-48824
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
16/07/2024
Last modified:
07/08/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
scsi: myrs: Fix crash in error case<br />
<br />
In myrs_detect(), cs->disable_intr is NULL when privdata->hw_init() fails<br />
with non-zero. In this case, myrs_cleanup(cs) will call a NULL ptr and<br />
crash the kernel.<br />
<br />
[ 1.105606] myrs 0000:00:03.0: Unknown Initialization Error 5A<br />
[ 1.105872] myrs 0000:00:03.0: Failed to initialize Controller<br />
[ 1.106082] BUG: kernel NULL pointer dereference, address: 0000000000000000<br />
[ 1.110774] Call Trace:<br />
[ 1.110950] myrs_cleanup+0xe4/0x150 [myrs]<br />
[ 1.111135] myrs_probe.cold+0x91/0x56a [myrs]<br />
[ 1.111302] ? DAC960_GEM_intr_handler+0x1f0/0x1f0 [myrs]<br />
[ 1.111500] local_pci_probe+0x48/0x90
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.4.180 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.101 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.16.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0e42c4a3d732517edc3766dd45a14e60d29dd929
- https://git.kernel.org/stable/c/1d6cd26605b4d662063a83c15c776b5299a1cb23
- https://git.kernel.org/stable/c/4db09593af0b0b4d7d4805ebb3273df51d7cc30d
- https://git.kernel.org/stable/c/5c5ceea00c8c9df150708e66cb9f2891192c1162
- https://git.kernel.org/stable/c/6207f35c213f6cb2fc3f13b5e77f08c710e1de19



