Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp-combo: fix NULL-deref on runtime resume Commit fc64623637da ("phy: qcom-qmp-combo,usb: add support for separate PCS_USB region") started treating the PCS_USB registers as potentially separate from the PCS registers but used the wrong base when no PCS_USB offset has been provided. Fix the PCS_USB base used at runtime resume to prevent dereferencing a NULL pointer on platforms that do not provide a PCS_USB offset (e.g. SC7180).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.0, < 6.0.9 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/04948e757148f870a31f4887ea2239403f516c3cPatch
- https://git.kernel.org/stable/c/c559a8b5cfa3db196ced0257b288f17027621348Patch
FAQ
What is CVE-2022-49848?
CVE-2022-49848 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp-combo: fix NULL-deref on runtime resume Commit fc64623637da ("phy: qcom-qmp-combo,usb: add support for separate PCS_...
How severe is CVE-2022-49848?
CVE-2022-49848 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49848?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.