CVE-2022-48663

In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the device's debugfs entries when unbinding the driver. This now causes a NULL-pointer dereference on module exit because the platform devices are unregistered *after* the global debugfs directory has been recursively removed. Fix it by unregistering the devices first.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

14 Jan 2025, 14:53

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/18352095a0d581f6aeb1e9fc9d68cc0152cd64b4 - () https://git.kernel.org/stable/c/18352095a0d581f6aeb1e9fc9d68cc0152cd64b4 - Patch
References () https://git.kernel.org/stable/c/af0bfabf06c74c260265c30ba81a34e7dec0e881 - () https://git.kernel.org/stable/c/af0bfabf06c74c260265c30ba81a34e7dec0e881 - Patch
References () https://git.kernel.org/stable/c/b7df41a6f79dfb18ba2203f8c5f0e9c0b9b57f68 - () https://git.kernel.org/stable/c/b7df41a6f79dfb18ba2203f8c5f0e9c0b9b57f68 - Patch
References () https://git.kernel.org/stable/c/bdea98b98f844bd8a983ca880893e509a8b4162f - () https://git.kernel.org/stable/c/bdea98b98f844bd8a983ca880893e509a8b4162f - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

21 Nov 2024, 07:33

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/18352095a0d581f6aeb1e9fc9d68cc0152cd64b4 - () https://git.kernel.org/stable/c/18352095a0d581f6aeb1e9fc9d68cc0152cd64b4 -
References () https://git.kernel.org/stable/c/af0bfabf06c74c260265c30ba81a34e7dec0e881 - () https://git.kernel.org/stable/c/af0bfabf06c74c260265c30ba81a34e7dec0e881 -
References () https://git.kernel.org/stable/c/b7df41a6f79dfb18ba2203f8c5f0e9c0b9b57f68 - () https://git.kernel.org/stable/c/b7df41a6f79dfb18ba2203f8c5f0e9c0b9b57f68 -
References () https://git.kernel.org/stable/c/bdea98b98f844bd8a983ca880893e509a8b4162f - () https://git.kernel.org/stable/c/bdea98b98f844bd8a983ca880893e509a8b4162f -
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: gpio: maqueta: corrige la desreferencia del puntero NULL al eliminar debugfs Ahora eliminamos las entradas debugfs del dispositivo al desvincular el controlador. Esto ahora provoca una desreferencia del puntero NULL al salir del módulo porque los dispositivos de la plataforma no están registrados *después* de que el directorio global debugfs se haya eliminado de forma recursiva. Solucionarlo cancelando el registro de los dispositivos primero.

28 Apr 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-28 13:15

Updated : 2025-01-14 14:53


NVD link : CVE-2022-48663

Mitre link : CVE-2022-48663

CVE.ORG link : CVE-2022-48663


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference