CVE-2022-49254

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
26/02/2025
Last modified:
22/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> media: ti-vpe: cal: Fix a NULL pointer dereference in cal_ctx_v4l2_init_formats()<br /> <br /> In cal_ctx_v4l2_init_formats(), devm_kzalloc() is assigned to<br /> ctx-&gt;active_fmt and there is a dereference of it after that, which could<br /> lead to NULL pointer dereference on failure of devm_kzalloc().<br /> <br /> Fix this bug by adding a NULL check of ctx-&gt;active_fmt.<br /> <br /> This bug was found by a static analyzer.<br /> <br /> Builds with &amp;#39;make allyesconfig&amp;#39; show no new warnings, and our static<br /> analyzer no longer warns about this code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.12 (including) 5.15.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.16.19 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.17 (including) 5.17.2 (excluding)