cbcvebase.
CVE-2022-49459
published 2025-02-26

CVE-2022-49459: In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/broadcom: Fix potential NULL dereference in sr_thermal_probe…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/broadcom: Fix potential NULL dereference in sr_thermal_probe platform_get_resource() may return NULL, add proper check to avoid potential NULL dereferencing.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 250e211057c7237dc75634b1372a1a3bd58dcd96 < b3461ccaa5d2588568d865faee285512ad448049b3461ccaa5d2588568d865faee285512ad448049
linuxlinux>= 250e211057c7237dc75634b1372a1a3bd58dcd96 < 79098339ac2065f4b4352ef5921628970b6f47e679098339ac2065f4b4352ef5921628970b6f47e6
linuxlinux>= 250e211057c7237dc75634b1372a1a3bd58dcd96 < ef1235c6514a58f274246cf4a2d5f4e40af539ceef1235c6514a58f274246cf4a2d5f4e40af539ce
linuxlinux>= 250e211057c7237dc75634b1372a1a3bd58dcd96 < ee9b6b02e8c140323ed46d6602d805ea735c7719ee9b6b02e8c140323ed46d6602d805ea735c7719
linuxlinux>= 250e211057c7237dc75634b1372a1a3bd58dcd96 < 61621e042c22b47d1eadee617bdd26835294b42561621e042c22b47d1eadee617bdd26835294b425
linuxlinux>= 250e211057c7237dc75634b1372a1a3bd58dcd96 < e20d136ec7d6f309989c447638365840d3424c8ee20d136ec7d6f309989c447638365840d3424c8e
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 5.1 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3
linuxlinux_kernel>= 5.5 < 5.10.1215.10.121

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.