CVE-2022-48879

MEDIUM

Linux Kernel - NULL Pointer Dereference in EFI Initialization Error Path

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: efi: fix NULL-deref in init error path In cases where runtime services are not supported or have been disabled, the runtime services workqueue will never have been allocated. Do not try to destroy the workqueue unconditionally in the unlikely event that EFI initialisation fails to avoid dereferencing a NULL pointer.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 15.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (26)
linux/Kernel < 4.19.270linux
linux/Kernel 4.20.0 - 5.4.229linux
linux/Kernel 5.11.0 - 6.1.7linux
linux/Kernel 5.5.0 - 5.10.164linux
linux/Kernel 5.9.0 - 5.15.89linux
Linux/Linux < 5.9
Linux/Linux 2ff3c97b47521d6700cc6485c7935908dcd2c27c - 585a0b2b3ae7903c6abee3087d09c69e955a7794
Linux/Linux 4.19.142 - 4.19.270
Linux/Linux 4.19.270 - 4.19.*
Linux/Linux 5.10.164 - 5.10.*
... and 16 more
Published Aug 21, 2024
Tracked Since Feb 18, 2026