CVE-2022-48908

MEDIUM

Linux kernel - Null Pointer Dereference

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe() During driver initialization, the pointer of card info, i.e. the variable 'ci' is required. However, the definition of 'com20020pci_id_table' reveals that this field is empty for some devices, which will cause null pointer dereference when initializing these devices. The following log reveals it: [ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f] [ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci] [ 3.975181] Call Trace: [ 3.976208] local_pci_probe+0x13f/0x210 [ 3.977248] pci_device_probe+0x34c/0x6d0 [ 3.977255] ? pci_uevent+0x470/0x470 [ 3.978265] really_probe+0x24c/0x8d0 [ 3.978273] __driver_probe_device+0x1b3/0x280 [ 3.979288] driver_probe_device+0x50/0x370 Fix this by checking whether the 'ci' is a null pointer first.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (27)
linux/Kernel 3.18.0 - 4.9.305linux
linux/Kernel 4.10.0 - 4.14.270linux
linux/Kernel 4.15.0 - 4.19.233linux
linux/Kernel 4.20.0 - 5.4.183linux
linux/Kernel 5.11.0 - 5.15.27linux
linux/Kernel 5.16.0 - 5.16.13linux
linux/Kernel 5.5.0 - 5.10.104linux
Linux/Linux < 3.18
Linux/Linux 3.18
Linux/Linux 4.14.270 - 4.14.*
... and 17 more
Published Aug 22, 2024
Tracked Since Feb 18, 2026