Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mfd: davinci_voicecodec: Fix possible null-ptr-deref davinci_vc_probe() It will cause null-ptr-deref when using 'res', if platform_get_resource() returns NULL, so move using 'res' after devm_ioremap_resource() that will check it to avoid null-ptr-deref. And use devm_platform_get_and_ioremap_resource() to simplify code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.4, < 5.4.198 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/2d00158a06efe6bbcd020108634ea0f2ed8b32f7Patch
- https://git.kernel.org/stable/c/311242c7703df0da14c206260b7e855f69cb0264Patch
- https://git.kernel.org/stable/c/49c1e32e7b3f301642a60448700ec531df981269Patch
- https://git.kernel.org/stable/c/5289795824b77489803b0802cd9edc13824a2d0bPatch
- https://git.kernel.org/stable/c/579944b9f38727d9ff570b58f83bc424e8af8398Patch
- https://git.kernel.org/stable/c/a1d4941d9a24999f680799f9bbde7f57351ca637Patch
FAQ
What is CVE-2022-49435?
CVE-2022-49435 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: mfd: davinci_voicecodec: Fix possible null-ptr-deref davinci_vc_probe() It will cause null-ptr-deref when using 'res', if platform...
How severe is CVE-2022-49435?
CVE-2022-49435 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49435?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.