CVE-2022-48663
published 2024-04-28CVE-2022-48663: In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the device's…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
gpio: mockup: fix NULL pointer dereference when removing debugfs
We now remove the device's debugfs entries when unbinding the driver.
This now causes a NULL-pointer dereference on module exit because the
platform devices are unregistered *after* the global debugfs directory
has been recursively removed. Fix it by unregistering the devices first.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | >= 303e6da99429510b1e4edf833afe90ac8542e747 < b7df41a6f79dfb18ba2203f8c5f0e9c0b9b57f68 | b7df41a6f79dfb18ba2203f8c5f0e9c0b9b57f68 |
| linux | linux | >= 3815e66c2183f3430490e450ba16779cf5214ec6 < bdea98b98f844bd8a983ca880893e509a8b4162f | bdea98b98f844bd8a983ca880893e509a8b4162f |
| linux | linux | >= 3a10e8edee2b45a654f1f7b05f747129ec84cf9d < 18352095a0d581f6aeb1e9fc9d68cc0152cd64b4 | 18352095a0d581f6aeb1e9fc9d68cc0152cd64b4 |
| linux | linux | >= 5.10.144 < 5.10.146 | 5.10.146 |
| linux | linux | >= 5.15.69 < 5.15.71 | 5.15.71 |
| linux | linux | >= 5.19.10 < 5.19.12 | 5.19.12 |
| linux | linux | >= bc55c1677edbe86a1c66a35e800df47dff16ad61 < af0bfabf06c74c260265c30ba81a34e7dec0e881 | af0bfabf06c74c260265c30ba81a34e7dec0e881 |
| linux | linux_kernel | >= 0 < 5.10.148-1 | 5.10.148-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 5.10.144 < 5.10.146 | 5.10.146 |
| linux | linux_kernel | >= 5.15.69 < 5.15.71 | 5.15.71 |
| linux | linux_kernel | >= 5.19.10 < 5.19.12 | 5.19.12 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: gpio: mockup: fix NULL pointer dereference when removing debugfs
vendor_redhat·2024-04-28·CVSS 5.5
CVE-2022-48663 [MEDIUM] CWE-476 kernel: gpio: mockup: fix NULL pointer dereference when removing debugfs
kernel: gpio: mockup: fix NULL pointer dereference when removing debugfs
In the Linux kernel, the following vulnerability has been resolved:
gpio: mockup: fix NULL pointer dereference when removing debugfs
We now remove the device's debugfs entries when unbinding the driver.
This now causes a NULL-pointer dereference on module exit because the
platform devices are unregistered *after* the global debugfs directory
has been recursively removed. Fix it by unregistering the devices first.
Statement: Red Hat Enterprise Linux 8 is not affected by this vulnerability as the affected source code is not enabled by default.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise
Debian
CVE-2022-48663: linux - In the Linux kernel, the following vulnerability has been resolved: gpio: mocku...
vendor_debian·2022·CVSS 5.5
CVE-2022-48663 [MEDIUM] CVE-2022-48663: linux - In the Linux kernel, the following vulnerability has been resolved: gpio: mocku...
In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the device's debugfs entries when unbinding the driver. This now causes a NULL-pointer dereference on module exit because the platform devices are unregistered *after* the global debugfs directory has been recursively removed. Fix it by unregistering the devices first.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.148-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
GHSA
GHSA-xgx4-jvp8-p2h2: In the Linux kernel, the following vulnerability has been resolved:
gpio: mockup: fix NULL pointer dereference when removing debugfs
We now remove t
ghsa_unreviewed·2024-04-28
CVE-2022-48663 [MEDIUM] CWE-476 GHSA-xgx4-jvp8-p2h2: In the Linux kernel, the following vulnerability has been resolved:
gpio: mockup: fix NULL pointer dereference when removing debugfs
We now remove t
In the Linux kernel, the following vulnerability has been resolved:
gpio: mockup: fix NULL pointer dereference when removing debugfs
We now remove the device's debugfs entries when unbinding the driver.
This now causes a NULL-pointer dereference on module exit because the
platform devices are unregistered *after* the global debugfs directory
has been recursively removed. Fix it by unregistering the devices first.
OSV
CVE-2022-48663: In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the
osv·2024-04-28·CVSS 5.5
CVE-2022-48663 [MEDIUM] CVE-2022-48663: In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the
In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the device's debugfs entries when unbinding the driver. This now causes a NULL-pointer dereference on module exit because the platform devices are unregistered *after* the global debugfs directory has been recursively removed. Fix it by unregistering the devices first.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/18352095a0d581f6aeb1e9fc9d68cc0152cd64b4https://git.kernel.org/stable/c/af0bfabf06c74c260265c30ba81a34e7dec0e881https://git.kernel.org/stable/c/b7df41a6f79dfb18ba2203f8c5f0e9c0b9b57f68https://git.kernel.org/stable/c/bdea98b98f844bd8a983ca880893e509a8b4162fhttps://git.kernel.org/stable/c/18352095a0d581f6aeb1e9fc9d68cc0152cd64b4https://git.kernel.org/stable/c/af0bfabf06c74c260265c30ba81a34e7dec0e881https://git.kernel.org/stable/c/b7df41a6f79dfb18ba2203f8c5f0e9c0b9b57f68https://git.kernel.org/stable/c/bdea98b98f844bd8a983ca880893e509a8b4162f
2024-04-28
Published