CVE-2022-49618

MEDIUM

Linux Kernel < 5.10.132, 5.11.0-5.15.56, 5.16.0-5.18.13 - NULL Pointer Dereference in pinctrl aspeed_pinmux_set_mux

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: pinctrl: aspeed: Fix potential NULL dereference in aspeed_pinmux_set_mux() pdesc could be null but still dereference pdesc->name and it will lead to a null pointer access. So we move a null check before dereference.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (15)
linux/Kernel 4.9.0 - 5.10.132linux
linux/Kernel 5.11.0 - 5.15.56linux
linux/Kernel 5.16.0 - 5.18.13linux
Linux/Linux < 4.9
Linux/Linux 4.9
Linux/Linux 4d3d0e4272d8d660f5f14f5abcf96fb4df1aa94b - 3cb392b64304a05bf647e2e44efacd9a1f3c3c6a
Linux/Linux 4d3d0e4272d8d660f5f14f5abcf96fb4df1aa94b - 84a85d3fef2e75b1fe9fc2af6f5267122555a1ed
Linux/Linux 4d3d0e4272d8d660f5f14f5abcf96fb4df1aa94b - e162a24f1dd06c0dcae71f2565c9f3da2827b98e
Linux/Linux 4d3d0e4272d8d660f5f14f5abcf96fb4df1aa94b - ef1e38532f4b2f0f3b460e938a2e7076c3bed5ee
Linux/Linux 5.10.132 - 5.10.*
... and 5 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026