CVE-2022-49435

medium

Description

In the Linux kernel, the following vulnerability has been resolved: mfd: davinci_voicecodec: Fix possible null-ptr-deref davinci_vc_probe() It will cause null-ptr-deref when using 'res', if platform_get_resource() returns NULL, so move using 'res' after devm_ioremap_resource() that will check it to avoid null-ptr-deref. And use devm_platform_get_and_ioremap_resource() to simplify code.

References

https://git.kernel.org/stable/c/a1d4941d9a24999f680799f9bbde7f57351ca637

https://git.kernel.org/stable/c/579944b9f38727d9ff570b58f83bc424e8af8398

https://git.kernel.org/stable/c/5289795824b77489803b0802cd9edc13824a2d0b

https://git.kernel.org/stable/c/49c1e32e7b3f301642a60448700ec531df981269

https://git.kernel.org/stable/c/311242c7703df0da14c206260b7e855f69cb0264

https://git.kernel.org/stable/c/2d00158a06efe6bbcd020108634ea0f2ed8b32f7

Details

Source: Mitre, NVD

Published: 2025-02-26

Updated: 2025-02-26

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium