cbcvebase.
CVE-2022-49453
published 2025-02-26

CVE-2022-49453: In the Linux kernel, the following vulnerability has been resolved: soc: ti: ti_sci_pm_domains: Check for null return of devm_kcalloc The allocation funciton…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: soc: ti: ti_sci_pm_domains: Check for null return of devm_kcalloc The allocation funciton devm_kcalloc may fail and return a null pointer, which would cause a null-pointer dereference later. It might be better to check it and directly return -ENOMEM just like the usage of devm_kcalloc in previous code.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 52835d59fc6cc7f3c3cfdb4a194ddc9ebd6c0c31 < 05efc4591f80582b6fe53366b70b6a35a42fd25505efc4591f80582b6fe53366b70b6a35a42fd255
linuxlinux>= 52835d59fc6cc7f3c3cfdb4a194ddc9ebd6c0c31 < 7cef9274fa1b8506949d74bc45aef072b890824a7cef9274fa1b8506949d74bc45aef072b890824a
linuxlinux>= 52835d59fc6cc7f3c3cfdb4a194ddc9ebd6c0c31 < c4e188869406b47ac3350920bf165be303cb1c96c4e188869406b47ac3350920bf165be303cb1c96
linuxlinux>= 52835d59fc6cc7f3c3cfdb4a194ddc9ebd6c0c31 < 01ba41a359622ab256ce4d4f8b94c67165ae3daf01ba41a359622ab256ce4d4f8b94c67165ae3daf
linuxlinux>= 52835d59fc6cc7f3c3cfdb4a194ddc9ebd6c0c31 < ba56291e297d28aa6eb82c5c1964fae2d7594746ba56291e297d28aa6eb82c5c1964fae2d7594746
linuxlinux_kernel< 5.10.1215.10.121
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.