cbcvebase.
CVE-2022-49506
published 2025-02-26

CVE-2022-49506: In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Add vblank register/unregister callback functions We encountered a kernel…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Add vblank register/unregister callback functions We encountered a kernel panic issue that callback data will be NULL when it's using in ovl irq handler. There is a timing issue between mtk_disp_ovl_irq_handler() and mtk_ovl_disable_vblank(). To resolve this issue, we use the flow to register/unregister vblank cb: - Register callback function and callback data when crtc creates. - Unregister callback function and callback data when crtc destroies. With this solution, we can assure callback data will not be NULL when vblank is disable.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 9b0704988b151824a51133dc4c921f4273c5d839 < 8a2dbdeccef6de47565638abdf3c25f41cdffc378a2dbdeccef6de47565638abdf3c25f41cdffc37
linuxlinux>= 9b0704988b151824a51133dc4c921f4273c5d839 < 8a265d9838bc3c63579002d55c2b2c655c4f8f268a265d9838bc3c63579002d55c2b2c655c4f8f26
linuxlinux>= 9b0704988b151824a51133dc4c921f4273c5d839 < 3a4027b5971fe2a94e32754f007d9d3c12c68ad13a4027b5971fe2a94e32754f007d9d3c12c68ad1
linuxlinux>= 9b0704988b151824a51133dc4c921f4273c5d839 < b74d921b900b6ce38c6247c0a1c86be9f3746493b74d921b900b6ce38c6247c0a1c86be9f3746493
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 5.12 < 5.15.545.15.54
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.