Record summary

CVE-2022-3113 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.

Description

An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Kernel

CVE ListLinux 5.16-rc6affected

Proofs of concept

1

Catalogued exploits

MetasploitRoxy-WI Prior to 6.1.1.0 Unauthenticated Command Injection RCEMetasploit exploitby Nuri Çilengir <nuri@prodaft.com>Not analyzed1 file

Ruby · linked to 2 vulnerabilities

Metasploit

PoC details

References

3