bugzilla.redhat.com
https://bugzilla.redhat.com/show_bug.cgi?id=2153053 CVE-2022-3113
MEDIUM
Roxy-WI Prior to 6.1.1.0 Unauthenticated Command Injection RCE
Record summary
CVE-2022-3113 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Kernel | CVE List | Linux 5.16-rc6 | affected |
Proofs of concept
1Catalogued exploits
MetasploitRoxy-WI Prior to 6.1.1.0 Unauthenticated Command Injection RCEMetasploit exploitby Nuri Çilengir <nuri@prodaft.com>Not analyzed1 file
References
3git.kernel.org
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?h=v5.19-rc2&id=e25a89f743b18c029bfbe5e1663ae0c7190912b0 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-3113