cbcvebase.
CVE-2022-49731
published 2025-02-26

CVE-2022-49731: In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo() In an unlikely (and…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo() In an unlikely (and probably wrong?) case that the 'ppi' parameter of ata_host_alloc_pinfo() points to an array starting with a NULL pointer, there's going to be a kernel oops as the 'pi' local variable won't get reassigned from the initial value of NULL. Initialize 'pi' instead to '&ata_dummy_port_info' to fix the possible kernel oops for good... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= f5cda257296fbd3683b1f568f2d94d3caaacf74d < ca4693e6e06e4fd2b240c0fec47aa2498c94848eca4693e6e06e4fd2b240c0fec47aa2498c94848e
linuxlinux>= f5cda257296fbd3683b1f568f2d94d3caaacf74d < 1ac5efee33f29e704226506d429b84575a5d66f81ac5efee33f29e704226506d429b84575a5d66f8
linuxlinux>= f5cda257296fbd3683b1f568f2d94d3caaacf74d < a810bd5af06977a847d1f202b22d7defd5c62497a810bd5af06977a847d1f202b22d7defd5c62497
linuxlinux>= f5cda257296fbd3683b1f568f2d94d3caaacf74d < 253334f84c81bc6a43af489f108c0bddad989eef253334f84c81bc6a43af489f108c0bddad989eef
linuxlinux>= f5cda257296fbd3683b1f568f2d94d3caaacf74d < 36cd19e7d4e5571d77a2ed20c5b6ef50cf57734a36cd19e7d4e5571d77a2ed20c5b6ef50cf57734a
linuxlinux>= f5cda257296fbd3683b1f568f2d94d3caaacf74d < ff128fbea720bf763fa345680dda5f050bc24a47ff128fbea720bf763fa345680dda5f050bc24a47
linuxlinux>= f5cda257296fbd3683b1f568f2d94d3caaacf74d < 07cbdb4807d369fbda73062a91b570c4dc5ec42907cbdb4807d369fbda73062a91b570c4dc5ec429
linuxlinux>= f5cda257296fbd3683b1f568f2d94d3caaacf74d < bf476fe22aa1851bab4728e0c49025a6a0bea307bf476fe22aa1851bab4728e0c49025a6a0bea307
linuxlinux_kernel< 4.9.3204.9.320
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.10 < 4.14.2854.14.285
linuxlinux_kernel>= 4.15 < 4.19.2494.19.249
linuxlinux_kernel>= 4.20 < 5.4.2005.4.200
linuxlinux_kernel>= 5.11 < 5.15.495.15.49
linuxlinux_kernel>= 5.16 < 5.18.65.18.6
linuxlinux_kernel>= 5.5 < 5.10.1245.10.124

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.