#VU104562 NULL pointer dereference in Linux kernel - CVE-2022-49335


Vulnerability identifier: #VU104562

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-49335

CWE-ID: CWE-476

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the amdgpu_cs_parser_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/15c3bcc9b5349d40207e5f8d4d799b8b4b7d13b8
https://git.kernel.org/stable/c/20b947e5a3c74c5084d661c097517a554989d462
https://git.kernel.org/stable/c/31ab27b14daaa75541a415c6794d6f3567fea44a
https://git.kernel.org/stable/c/70276460e914d560e96bfc208695a872fe9469c9
https://git.kernel.org/stable/c/7086a23890d255bb5761604e39174b20d06231a4
https://git.kernel.org/stable/c/8189f44270db1be78169e11eec51a3eeb980bc63
https://git.kernel.org/stable/c/aa25acbe96692e4bf8482311c293f72d8c6034c0
https://git.kernel.org/stable/c/be585921f29df5422a39c952d188b418ad48ffab
https://git.kernel.org/stable/c/c12984cdb077b9042d2dc20ca18cb16a87bcc774


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability