CVE-2022-48908
published 2024-08-22CVE-2022-48908: In the Linux kernel, the following vulnerability has been resolved: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe() During driver…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
During driver initialization, the pointer of card info, i.e. the
variable 'ci' is required. However, the definition of
'com20020pci_id_table' reveals that this field is empty for some
devices, which will cause null pointer dereference when initializing
these devices.
The following log reveals it:
[ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]
[ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci]
[ 3.975181] Call Trace:
[ 3.976208] local_pci_probe+0x13f/0x210
[ 3.977248] pci_device_probe+0x34c/0x6d0
[ 3.977255] ? pci_uevent+0x470/0x470
[ 3.978265] really_probe+0x24c/0x8d0
[ 3.978273] __driver_probe_device+0x1b3/0x280
[ 3.979288] driver_probe_device+0x50/0x370
Fix this by checking whether the 'ci' is a null pointer first.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.14-1 (bookworm) | linux 5.16.14-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < 8e3bc7c5bbf87e86e9cd652ca2a9166942d86206 | 8e3bc7c5bbf87e86e9cd652ca2a9166942d86206 |
| linux | linux | >= 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < b1ee6b9340a38bdb9e5c90f0eac5b22b122c3049 | b1ee6b9340a38bdb9e5c90f0eac5b22b122c3049 |
| linux | linux | >= 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < b838add93e1dd98210482dc433768daaf752bdef | b838add93e1dd98210482dc433768daaf752bdef |
| linux | linux | >= 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < e50c589678e50f8d574612e473ca60ef45190896 | e50c589678e50f8d574612e473ca60ef45190896 |
| linux | linux | >= 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < 5f394102ee27dbf051a4e283390cd8d1759dacea | 5f394102ee27dbf051a4e283390cd8d1759dacea |
| linux | linux | >= 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < ea372aab54903310756217d81610901a8e66cb7d | ea372aab54903310756217d81610901a8e66cb7d |
| linux | linux | >= 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < ca0bdff4249a644f2ca7a49d410d95b8dacf1f72 | ca0bdff4249a644f2ca7a49d410d95b8dacf1f72 |
| linux | linux | >= 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < bd6f1fd5d33dfe5d1b4f2502d3694a7cc13f166d | bd6f1fd5d33dfe5d1b4f2502d3694a7cc13f166d |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.106-1 | 5.10.106-1 |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 3.18 < 4.9.305 | 4.9.305 |
| linux | linux_kernel | >= 4.10 < 4.14.270 | 4.14.270 |
| linux | linux_kernel | >= 4.15 < 4.19.233 | 4.19.233 |
| linux | linux_kernel | >= 4.20 < 5.4.183 | 5.4.183 |
| linux | linux_kernel | >= 5.11 < 5.15.27 | 5.15.27 |
| linux | linux_kernel | >= 5.16 < 5.16.13 | 5.16.13 |
| linux | linux_kernel | >= 5.5 < 5.10.104 | 5.10.104 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
vendor_redhat·2024-08-22·CVSS 5.5
CVE-2022-48908 [MEDIUM] CWE-476 kernel: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
kernel: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
In the Linux kernel, the following vulnerability has been resolved:
net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
During driver initialization, the pointer of card info, i.e. the
variable 'ci' is required. However, the definition of
'com20020pci_id_table' reveals that this field is empty for some
devices, which will cause null pointer dereference when initializing
these devices.
The following log reveals it:
[ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]
[ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci]
[ 3.975181] Call Trace:
[ 3.976208] local_pci_probe+0x13f/0x210
[ 3.977248] pci_device_probe+0x34c/0x6d0
[ 3.977255] ? pci_uevent+0x470/0x470
[
Debian
CVE-2022-48908: linux - In the Linux kernel, the following vulnerability has been resolved: net: arcnet...
vendor_debian·2022·CVSS 5.5
CVE-2022-48908 [MEDIUM] CVE-2022-48908: linux - In the Linux kernel, the following vulnerability has been resolved: net: arcnet...
In the Linux kernel, the following vulnerability has been resolved: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe() During driver initialization, the pointer of card info, i.e. the variable 'ci' is required. However, the definition of 'com20020pci_id_table' reveals that this field is empty for some devices, which will cause null pointer dereference when initializing these devices. The following log reveals it: [ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f] [ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci] [ 3.975181] Call Trace: [ 3.976208] local_pci_probe+0x13f/0x210 [ 3.977248] pci_device_probe+0x34c/0x6d0 [ 3.977255] ? pci_uevent+0x470/0x470 [ 3.978265] really_probe+0x24c/0x8d0 [ 3.978273] __driver_probe_device+0x1b3
OSV
CVE-2022-48908: In the Linux kernel, the following vulnerability has been resolved: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe() During driver ini
osv·2024-08-22·CVSS 5.5
CVE-2022-48908 [MEDIUM] CVE-2022-48908: In the Linux kernel, the following vulnerability has been resolved: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe() During driver ini
In the Linux kernel, the following vulnerability has been resolved: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe() During driver initialization, the pointer of card info, i.e. the variable 'ci' is required. However, the definition of 'com20020pci_id_table' reveals that this field is empty for some devices, which will cause null pointer dereference when initializing these devices. The following log reveals it: [ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f] [ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci] [ 3.975181] Call Trace: [ 3.976208] local_pci_probe+0x13f/0x210 [ 3.977248] pci_device_probe+0x34c/0x6d0 [ 3.977255] ? pci_uevent+0x470/0x470 [ 3.978265] really_probe+0x24c/0x8d0 [ 3.978273] __driver_probe_device+0x1b3
GHSA
GHSA-cp24-c7w4-6gh4: In the Linux kernel, the following vulnerability has been resolved:
net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
During driver i
ghsa_unreviewed·2024-08-22
CVE-2022-48908 [MEDIUM] CWE-476 GHSA-cp24-c7w4-6gh4: In the Linux kernel, the following vulnerability has been resolved:
net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
During driver i
In the Linux kernel, the following vulnerability has been resolved:
net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
During driver initialization, the pointer of card info, i.e. the
variable 'ci' is required. However, the definition of
'com20020pci_id_table' reveals that this field is empty for some
devices, which will cause null pointer dereference when initializing
these devices.
The following log reveals it:
[ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]
[ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci]
[ 3.975181] Call Trace:
[ 3.976208] local_pci_probe+0x13f/0x210
[ 3.977248] pci_device_probe+0x34c/0x6d0
[ 3.977255] ? pci_uevent+0x470/0x470
[ 3.978265] really_probe+0x24c/0x8d0
[ 3.978273] __driver_probe_device+0
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/5f394102ee27dbf051a4e283390cd8d1759daceahttps://git.kernel.org/stable/c/8e3bc7c5bbf87e86e9cd652ca2a9166942d86206https://git.kernel.org/stable/c/b1ee6b9340a38bdb9e5c90f0eac5b22b122c3049https://git.kernel.org/stable/c/b838add93e1dd98210482dc433768daaf752bdefhttps://git.kernel.org/stable/c/bd6f1fd5d33dfe5d1b4f2502d3694a7cc13f166dhttps://git.kernel.org/stable/c/ca0bdff4249a644f2ca7a49d410d95b8dacf1f72https://git.kernel.org/stable/c/e50c589678e50f8d574612e473ca60ef45190896https://git.kernel.org/stable/c/ea372aab54903310756217d81610901a8e66cb7d
2024-08-22
Published