CVE-2022-49489
published 2025-02-26CVE-2022-49489: In the Linux kernel, the following vulnerability has been resolved: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume
BUG: Unable to handle kernel paging request at virtual address 006b6b6b6b6b6be3
Call trace:
dpu_vbif_init_memtypes+0x40/0xb8
dpu_runtime_resume+0xcc/0x1c0
pm_generic_runtime_resume+0x30/0x44
__genpd_runtime_resume+0x68/0x7c
genpd_runtime_resume+0x134/0x258
__rpm_callback+0x98/0x138
rpm_callback+0x30/0x88
rpm_resume+0x36c/0x49c
__pm_runtime_resume+0x80/0xb0
dpu_core_irq_uninstall+0x30/0xb0
dpu_irq_uninstall+0x18/0x24
msm_drm_uninit+0xd8/0x16c
Patchwork: https://patchwork.freedesktop.org/patch/483255/
[DB: fixed Fixes tag]
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 25fdd5933e4c0f5fe2ea5cd59994f8ac5fbe90ef < aa4cb188988dc6f1b3f4917d4dbc452150a5d871 | aa4cb188988dc6f1b3f4917d4dbc452150a5d871 |
| linux | linux | >= 25fdd5933e4c0f5fe2ea5cd59994f8ac5fbe90ef < ef10d0c68e8608848cd58fca2589685718426607 | ef10d0c68e8608848cd58fca2589685718426607 |
| linux | linux | >= 25fdd5933e4c0f5fe2ea5cd59994f8ac5fbe90ef < 134760263f6441741db0b2970e7face6b34b6d1c | 134760263f6441741db0b2970e7face6b34b6d1c |
| linux | linux | >= 25fdd5933e4c0f5fe2ea5cd59994f8ac5fbe90ef < ef4bdaac7cb5416f236613ed9337ff0ea8ee329b | ef4bdaac7cb5416f236613ed9337ff0ea8ee329b |
| linux | linux | >= 25fdd5933e4c0f5fe2ea5cd59994f8ac5fbe90ef < 97ac682b6f7d36be5d934f86c9911066540a68f1 | 97ac682b6f7d36be5d934f86c9911066540a68f1 |
| linux | linux | >= 25fdd5933e4c0f5fe2ea5cd59994f8ac5fbe90ef < 5b0adf5cbf3b74721e4e4c4e0cadc91b8df8bcc2 | 5b0adf5cbf3b74721e4e4c4e0cadc91b8df8bcc2 |
| linux | linux | >= 25fdd5933e4c0f5fe2ea5cd59994f8ac5fbe90ef < fa5186b279ecf44b14fb435540d2065be91cb1ed | fa5186b279ecf44b14fb435540d2065be91cb1ed |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 4.19 < 4.19.247 | 4.19.247 |
| linux | linux_kernel | >= 4.20 < 5.4.198 | 5.4.198 |
| linux | linux_kernel | >= 5.11 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
| linux | linux_kernel | >= 5.5 < 5.10.121 | 5.10.121 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5wpm-mmfv-62g9: In the Linux kernel, the following vulnerability has been resolved:
drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free duri
ghsa_unreviewed·2025-03-06
CVE-2022-49489 [HIGH] CWE-416 GHSA-5wpm-mmfv-62g9: In the Linux kernel, the following vulnerability has been resolved:
drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free duri
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume
BUG: Unable to handle kernel paging request at virtual address 006b6b6b6b6b6be3
Call trace:
dpu_vbif_init_memtypes+0x40/0xb8
dpu_runtime_resume+0xcc/0x1c0
pm_generic_runtime_resume+0x30/0x44
__genpd_runtime_resume+0x68/0x7c
genpd_runtime_resume+0x134/0x258
__rpm_callback+0x98/0x138
rpm_callback+0x30/0x88
rpm_resume+0x36c/0x49c
__pm_runtime_resume+0x80/0xb0
dpu_core_irq_uninstall+0x30/0xb0
dpu_irq_uninstall+0x18/0x24
msm_drm_uninit+0xd8/0x16c
Patchwork: https://patchwork.freedesktop.org/patch/483255/
[DB: fixed Fixes tag]
OSV
CVE-2022-49489: In the Linux kernel, the following vulnerability has been resolved: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free durin
osv·2025-02-26·CVSS 7.8
CVE-2022-49489 [HIGH] CVE-2022-49489: In the Linux kernel, the following vulnerability has been resolved: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free durin
In the Linux kernel, the following vulnerability has been resolved: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume BUG: Unable to handle kernel paging request at virtual address 006b6b6b6b6b6be3 Call trace: dpu_vbif_init_memtypes+0x40/0xb8 dpu_runtime_resume+0xcc/0x1c0 pm_generic_runtime_resume+0x30/0x44 __genpd_runtime_resume+0x68/0x7c genpd_runtime_resume+0x134/0x258 __rpm_callback+0x98/0x138 rpm_callback+0x30/0x88 rpm_resume+0x36c/0x49c __pm_runtime_resume+0x80/0xb0 dpu_core_irq_uninstall+0x30/0xb0 dpu_irq_uninstall+0x18/0x24 msm_drm_uninit+0xd8/0x16c Patchwork: https://patchwork.freedesktop.org/patch/483255/ [DB: fixed Fixes tag]
Red Hat
kernel: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49489 [HIGH] kernel: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume
kernel: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume
BUG: Unable to handle kernel paging request at virtual address 006b6b6b6b6b6be3
Call trace:
dpu_vbif_init_memtypes+0x40/0xb8
dpu_runtime_resume+0xcc/0x1c0
pm_generic_runtime_resume+0x30/0x44
__genpd_runtime_resume+0x68/0x7c
genpd_runtime_resume+0x134/0x258
__rpm_callback+0x98/0x138
rpm_callback+0x30/0x88
rpm_resume+0x36c/0x49c
__pm_runtime_resume+0x80/0xb0
dpu_core_irq_uninstall+0x30/0xb0
dpu_irq_uninstall+0x18/0x24
msm_drm_uninit+0xd8/0x16c
Patchwork: https://patchwork.freedesktop.org/patch/483255/
[DB: fixed Fix
Debian
CVE-2022-49489: linux - In the Linux kernel, the following vulnerability has been resolved: drm/msm/dis...
vendor_debian·2022·CVSS 7.8
CVE-2022-49489 [HIGH] CVE-2022-49489: linux - In the Linux kernel, the following vulnerability has been resolved: drm/msm/dis...
In the Linux kernel, the following vulnerability has been resolved: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume BUG: Unable to handle kernel paging request at virtual address 006b6b6b6b6b6be3 Call trace: dpu_vbif_init_memtypes+0x40/0xb8 dpu_runtime_resume+0xcc/0x1c0 pm_generic_runtime_resume+0x30/0x44 __genpd_runtime_resume+0x68/0x7c genpd_runtime_resume+0x134/0x258 __rpm_callback+0x98/0x138 rpm_callback+0x30/0x88 rpm_resume+0x36c/0x49c __pm_runtime_resume+0x80/0xb0 dpu_core_irq_uninstall+0x30/0xb0 dpu_irq_uninstall+0x18/0x24 msm_drm_uninit+0xd8/0x16c Patchwork: https://patchwork.freedesktop.org/patch/483255/ [DB: fixed Fixes tag]
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved (fixed in 5.10.127-1)
forky: res
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/134760263f6441741db0b2970e7face6b34b6d1chttps://git.kernel.org/stable/c/5b0adf5cbf3b74721e4e4c4e0cadc91b8df8bcc2https://git.kernel.org/stable/c/97ac682b6f7d36be5d934f86c9911066540a68f1https://git.kernel.org/stable/c/aa4cb188988dc6f1b3f4917d4dbc452150a5d871https://git.kernel.org/stable/c/ef10d0c68e8608848cd58fca2589685718426607https://git.kernel.org/stable/c/ef4bdaac7cb5416f236613ed9337ff0ea8ee329bhttps://git.kernel.org/stable/c/fa5186b279ecf44b14fb435540d2065be91cb1ed
2025-02-26
Published