CVE-2022-49273
published 2025-02-26CVE-2022-49273: In the Linux kernel, the following vulnerability has been resolved: rtc: pl031: fix rtc features null pointer dereference When there is no interrupt line, rtc…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
rtc: pl031: fix rtc features null pointer dereference
When there is no interrupt line, rtc alarm feature is disabled.
The clearing of the alarm feature bit was being done prior to allocations
of ldata->rtc device, resulting in a null pointer dereference.
Clear RTC_FEATURE_ALARM after the rtc device is allocated.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= d9b0dd54a1943f47a381a474f8ea2c94466110c0 < cd2722e411e8ab7e5ae41102f6925fa13dffdac5 | cd2722e411e8ab7e5ae41102f6925fa13dffdac5 |
| linux | linux | >= d9b0dd54a1943f47a381a474f8ea2c94466110c0 < d274ce4a3dfd0b9a292667535578359b865765cb | d274ce4a3dfd0b9a292667535578359b865765cb |
| linux | linux | >= d9b0dd54a1943f47a381a474f8ea2c94466110c0 < 1b915703964f7e636961df04c540261dc55c6c70 | 1b915703964f7e636961df04c540261dc55c6c70 |
| linux | linux | >= d9b0dd54a1943f47a381a474f8ea2c94466110c0 < ea6af39f3da50c86367a71eb3cc674ade3ed244c | ea6af39f3da50c86367a71eb3cc674ade3ed244c |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 5.12 < 5.15.33 | 5.15.33 |
| linux | linux_kernel | >= 5.16 < 5.16.19 | 5.16.19 |
| linux | linux_kernel | >= 5.17 < 5.17.2 | 5.17.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: rtc: pl031: fix rtc features null pointer dereference
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49273 [MEDIUM] CWE-476 kernel: rtc: pl031: fix rtc features null pointer dereference
kernel: rtc: pl031: fix rtc features null pointer dereference
In the Linux kernel, the following vulnerability has been resolved:
rtc: pl031: fix rtc features null pointer dereference
When there is no interrupt line, rtc alarm feature is disabled.
The clearing of the alarm feature bit was being done prior to allocations
of ldata->rtc device, resulting in a null pointer dereference.
Clear RTC_FEATURE_ALARM after the rtc device is allocated.
A flaw was found in the rtc-pl031 module in the Linux kernel. The alarm feature bit was cleaned before device initialization, which caused a NULL pointer dereference when there was no interrupt line. This resulted in a system crash and a denial of service.
Statement: The rtc-pl031 module as shipped in the Linux kernel in Red Hat Enterprise Linux 6, 7
Debian
CVE-2022-49273: linux - In the Linux kernel, the following vulnerability has been resolved: rtc: pl031:...
vendor_debian·2022·CVSS 5.5
CVE-2022-49273 [MEDIUM] CVE-2022-49273: linux - In the Linux kernel, the following vulnerability has been resolved: rtc: pl031:...
In the Linux kernel, the following vulnerability has been resolved: rtc: pl031: fix rtc features null pointer dereference When there is no interrupt line, rtc alarm feature is disabled. The clearing of the alarm feature bit was being done prior to allocations of ldata->rtc device, resulting in a null pointer dereference. Clear RTC_FEATURE_ALARM after the rtc device is allocated.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.17.3-1)
GHSA
GHSA-rq3p-6qpw-48cx: In the Linux kernel, the following vulnerability has been resolved:
rtc: pl031: fix rtc features null pointer dereference
When there is no interrupt
ghsa_unreviewed·2025-04-14
CVE-2022-49273 [MEDIUM] CWE-476 GHSA-rq3p-6qpw-48cx: In the Linux kernel, the following vulnerability has been resolved:
rtc: pl031: fix rtc features null pointer dereference
When there is no interrupt
In the Linux kernel, the following vulnerability has been resolved:
rtc: pl031: fix rtc features null pointer dereference
When there is no interrupt line, rtc alarm feature is disabled.
The clearing of the alarm feature bit was being done prior to allocations
of ldata->rtc device, resulting in a null pointer dereference.
Clear RTC_FEATURE_ALARM after the rtc device is allocated.
OSV
CVE-2022-49273: In the Linux kernel, the following vulnerability has been resolved: rtc: pl031: fix rtc features null pointer dereference When there is no interrupt l
osv·2025-02-26·CVSS 5.5
CVE-2022-49273 [MEDIUM] CVE-2022-49273: In the Linux kernel, the following vulnerability has been resolved: rtc: pl031: fix rtc features null pointer dereference When there is no interrupt l
In the Linux kernel, the following vulnerability has been resolved: rtc: pl031: fix rtc features null pointer dereference When there is no interrupt line, rtc alarm feature is disabled. The clearing of the alarm feature bit was being done prior to allocations of ldata->rtc device, resulting in a null pointer dereference. Clear RTC_FEATURE_ALARM after the rtc device is allocated.
No detection rules found.
No public exploits indexed.
2025-02-26
Published