Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: invalid parameter check in msm_dsi_phy_enable The function performs a check on the "phy" input parameter, however, it is used before the check. Initialize the "dev" variable after the sanity check to avoid a possible NULL pointer dereference. Addresses-Coverity-ID: 1493860 ("Null pointer dereference")
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.3, < 4.14.265 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/2b7e7df1eacd280e561ede3e977853606871c951Patch
- https://git.kernel.org/stable/c/56480fb10b976581a363fd168dc2e4fbee87a1a7Patch
- https://git.kernel.org/stable/c/581317b1f001b7509041544d7019b75571daa100Patch
- https://git.kernel.org/stable/c/5e761a2287234bc402ba7ef07129f5103bcd775cPatch
- https://git.kernel.org/stable/c/6d9f8ba28f3747ca0f910a363e46f1114856dbbePatch
- https://git.kernel.org/stable/c/79c0b5287ded74f4eacde4dfd8aa0a76cbd853b5Patch
- https://git.kernel.org/stable/c/ca63eeb70fcb53c42e1fe54e1735a54d8e7759fdPatch
- https://git.kernel.org/stable/c/2b7e7df1eacd280e561ede3e977853606871c951Patch
- https://git.kernel.org/stable/c/56480fb10b976581a363fd168dc2e4fbee87a1a7Patch
- https://git.kernel.org/stable/c/581317b1f001b7509041544d7019b75571daa100Patch
- https://git.kernel.org/stable/c/5e761a2287234bc402ba7ef07129f5103bcd775cPatch
- https://git.kernel.org/stable/c/6d9f8ba28f3747ca0f910a363e46f1114856dbbePatch
- https://git.kernel.org/stable/c/79c0b5287ded74f4eacde4dfd8aa0a76cbd853b5Patch
- https://git.kernel.org/stable/c/ca63eeb70fcb53c42e1fe54e1735a54d8e7759fdPatch
FAQ
What is CVE-2022-48756?
CVE-2022-48756 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: invalid parameter check in msm_dsi_phy_enable The function performs a check on the "phy" input parameter, however, it...
How severe is CVE-2022-48756?
CVE-2022-48756 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48756?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.