Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: i2c: mux: reg: check return value after calling platform_get_resource() It will cause null-ptr-deref in resource_size(), if platform_get_resource() returns NULL, move calling resource_size() after devm_ioremap_resource() that will check 'res' to avoid null-ptr-deref. And use devm_platform_get_and_ioremap_resource() to simplify code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.3, < 5.10.163 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/2d47b79d2bd39cc6369eccf94a06568d84c906aePatch
- https://git.kernel.org/stable/c/61df25c41b8e0d2c988ccf17139f70075a2e1ba4Patch
- https://git.kernel.org/stable/c/8212800943997fab61874550278d653cb378c60cPatch
- https://git.kernel.org/stable/c/f5049b3ad9446203b916ee375f30fa217735f63aPatch
- https://git.kernel.org/stable/c/f7a440c89b6d460154efeb058272760e41bdfea8Patch
FAQ
What is CVE-2022-50364?
CVE-2022-50364 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: i2c: mux: reg: check return value after calling platform_get_resource() It will cause null-ptr-deref in resource_size(), if platfo...
How severe is CVE-2022-50364?
CVE-2022-50364 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50364?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.