CVE-2022-48879
published 2024-08-21CVE-2022-48879: In the Linux kernel, the following vulnerability has been resolved: efi: fix NULL-deref in init error path In cases where runtime services are not supported or…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
efi: fix NULL-deref in init error path
In cases where runtime services are not supported or have been disabled,
the runtime services workqueue will never have been allocated.
Do not try to destroy the workqueue unconditionally in the unlikely
event that EFI initialisation fails to avoid dereferencing a NULL
pointer.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.7-1 (bookworm) | linux 6.1.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 2ff3c97b47521d6700cc6485c7935908dcd2c27c < 585a0b2b3ae7903c6abee3087d09c69e955a7794 | 585a0b2b3ae7903c6abee3087d09c69e955a7794 |
| linux | linux | >= 4.19.142 < 4.19.270 | 4.19.270 |
| linux | linux | >= 5.4.61 < 5.4.229 | 5.4.229 |
| linux | linux | >= 5.7.18 < 5.8 | 5.8 |
| linux | linux | >= 5.8.4 < 5.9 | 5.9 |
| linux | linux | >= 5167f194da6947e19a3e970485ee3ccb44f7958d < 5fcf75a8a4c3e7ee9122d143684083c9faf20452 | 5fcf75a8a4c3e7ee9122d143684083c9faf20452 |
| linux | linux | >= 98086df8b70c06234a8f4290c46064e44dafa0ed < 4ca71bc0e1995d15486cd7b60845602a28399cb5 | 4ca71bc0e1995d15486cd7b60845602a28399cb5 |
| linux | linux | >= 98086df8b70c06234a8f4290c46064e44dafa0ed < e2ea55564229e4bea1474af15b111b3a3043b76f | e2ea55564229e4bea1474af15b111b3a3043b76f |
| linux | linux | >= 98086df8b70c06234a8f4290c46064e44dafa0ed < adc96d30f6503d30dc68670c013716f1d9fcc747 | adc96d30f6503d30dc68670c013716f1d9fcc747 |
| linux | linux | >= 98086df8b70c06234a8f4290c46064e44dafa0ed < 703c13fe3c9af557d312f5895ed6a5fda2711104 | 703c13fe3c9af557d312f5895ed6a5fda2711104 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 4.19.142 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 5.11 < 5.15.89 | 5.15.89 |
| linux | linux_kernel | >= 5.16 < 6.1.7 | 6.1.7 |
| linux | linux_kernel | >= 5.4.61 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.9 < 5.10.164 | 5.10.164 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-48879: In the Linux kernel, the following vulnerability has been resolved: efi: fix NULL-deref in init error path In cases where runtime services are not sup
osv·2024-08-21·CVSS 5.5
CVE-2022-48879 [MEDIUM] CVE-2022-48879: In the Linux kernel, the following vulnerability has been resolved: efi: fix NULL-deref in init error path In cases where runtime services are not sup
In the Linux kernel, the following vulnerability has been resolved: efi: fix NULL-deref in init error path In cases where runtime services are not supported or have been disabled, the runtime services workqueue will never have been allocated. Do not try to destroy the workqueue unconditionally in the unlikely event that EFI initialisation fails to avoid dereferencing a NULL pointer.
GHSA
GHSA-p9p6-vvr2-mf86: In the Linux kernel, the following vulnerability has been resolved:
efi: fix NULL-deref in init error path
In cases where runtime services are not s
ghsa_unreviewed·2024-08-21
CVE-2022-48879 [MEDIUM] CWE-476 GHSA-p9p6-vvr2-mf86: In the Linux kernel, the following vulnerability has been resolved:
efi: fix NULL-deref in init error path
In cases where runtime services are not s
In the Linux kernel, the following vulnerability has been resolved:
efi: fix NULL-deref in init error path
In cases where runtime services are not supported or have been disabled,
the runtime services workqueue will never have been allocated.
Do not try to destroy the workqueue unconditionally in the unlikely
event that EFI initialisation fails to avoid dereferencing a NULL
pointer.
Red Hat
kernel: efi: fix NULL-deref in init error path
vendor_redhat·2024-08-21·CVSS 5.5
CVE-2022-48879 [MEDIUM] CWE-476 kernel: efi: fix NULL-deref in init error path
kernel: efi: fix NULL-deref in init error path
In the Linux kernel, the following vulnerability has been resolved:
efi: fix NULL-deref in init error path
In cases where runtime services are not supported or have been disabled,
the runtime services workqueue will never have been allocated.
Do not try to destroy the workqueue unconditionally in the unlikely
event that EFI initialisation fails to avoid dereferencing a NULL
pointer.
Statement: Following issue marked as moderate with "not affected" for Red Hat Enterprise Linux, as it is not vulnerable to this CVE. This is because the CVE does not impact the versions or configurations of the Linux kernel used in Red Hat's distributions. Additionally, some RHEL versions may be marked as "will not fix" due to the minimal impact of the issue, and
Debian
CVE-2022-48879: linux - In the Linux kernel, the following vulnerability has been resolved: efi: fix NU...
vendor_debian·2022·CVSS 5.5
CVE-2022-48879 [MEDIUM] CVE-2022-48879: linux - In the Linux kernel, the following vulnerability has been resolved: efi: fix NU...
In the Linux kernel, the following vulnerability has been resolved: efi: fix NULL-deref in init error path In cases where runtime services are not supported or have been disabled, the runtime services workqueue will never have been allocated. Do not try to destroy the workqueue unconditionally in the unlikely event that EFI initialisation fails to avoid dereferencing a NULL pointer.
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.7-1)
sid: resolved (fixed in 6.1.7-1)
trixie: resolved (fixed in 6.1.7-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/4ca71bc0e1995d15486cd7b60845602a28399cb5https://git.kernel.org/stable/c/585a0b2b3ae7903c6abee3087d09c69e955a7794https://git.kernel.org/stable/c/5fcf75a8a4c3e7ee9122d143684083c9faf20452https://git.kernel.org/stable/c/703c13fe3c9af557d312f5895ed6a5fda2711104https://git.kernel.org/stable/c/adc96d30f6503d30dc68670c013716f1d9fcc747https://git.kernel.org/stable/c/e2ea55564229e4bea1474af15b111b3a3043b76f
2024-08-21
Published