#VU104591 NULL pointer dereference in Linux kernel - CVE-2022-49495


Vulnerability identifier: #VU104591

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-49495

CWE-ID: CWE-476

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the msm_hdmi_init() function in drivers/gpu/drm/msm/hdmi/hdmi.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/0978fcce91b90b561b8c82e7c492ba9fc8440eef
https://git.kernel.org/stable/c/2b3ed7547b1a052209da6c4ab886ffe0eed88c42
https://git.kernel.org/stable/c/4cd66a8016b872a153bf892fe4258cbc0dacf5b1
https://git.kernel.org/stable/c/6369dda4a2209142ab819f01d3d2076d81e3ebdd
https://git.kernel.org/stable/c/9cb1ee33efccb8b107ee04b7b3441820de3fd2da
https://git.kernel.org/stable/c/9f5495a5c51c1d11c6ffc13aa2befffec0c2651a
https://git.kernel.org/stable/c/a36e506711548df923ceb7ec9f6001375be799a5
https://git.kernel.org/stable/c/c1bfacf0daf25a5fc7d667399d6ff2dffda84cd8
https://git.kernel.org/stable/c/d9cb951d11a4ace4de5c50b1178ad211de17079e


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability