Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: rtc: pl031: fix rtc features null pointer dereference When there is no interrupt line, rtc alarm feature is disabled. The clearing of the alarm feature bit was being done prior to allocations of ldata->rtc device, resulting in a null pointer dereference. Clear RTC_FEATURE_ALARM after the rtc device is allocated.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.12, < 5.15.33 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/1b915703964f7e636961df04c540261dc55c6c70Patch
- https://git.kernel.org/stable/c/cd2722e411e8ab7e5ae41102f6925fa13dffdac5Patch
- https://git.kernel.org/stable/c/d274ce4a3dfd0b9a292667535578359b865765cbPatch
- https://git.kernel.org/stable/c/ea6af39f3da50c86367a71eb3cc674ade3ed244cPatch
FAQ
What is CVE-2022-49273?
CVE-2022-49273 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: rtc: pl031: fix rtc features null pointer dereference When there is no interrupt line, rtc alarm feature is disabled. The clearin...
How severe is CVE-2022-49273?
CVE-2022-49273 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49273?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.