[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2025022658-CVE-2022-49445-244f@gregkh>
Date: Wed, 26 Feb 2025 03:11:59 +0100
From: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To: linux-cve-announce@...r.kernel.org
Cc: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
Subject: CVE-2022-49445: pinctrl: renesas: core: Fix possible null-ptr-deref in sh_pfc_map_resources()
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: renesas: core: Fix possible null-ptr-deref in sh_pfc_map_resources()
It will cause null-ptr-deref when using 'res', if platform_get_resource()
returns NULL, so move using 'res' after devm_ioremap_resource() that
will check it to avoid null-ptr-deref.
And use devm_platform_get_and_ioremap_resource() to simplify code.
The Linux kernel CVE team has assigned CVE-2022-49445 to this issue.
Affected and fixed versions
===========================
Issue introduced in 4.3 with commit c7977ec4a33633c8e8d9267dd014356cf857351c and fixed in 5.10.121 with commit f991879762392c19661af5b722578089a12b305f
Issue introduced in 4.3 with commit c7977ec4a33633c8e8d9267dd014356cf857351c and fixed in 5.15.46 with commit 5ed0519d425619b435150372cce2ffeec71581fa
Issue introduced in 4.3 with commit c7977ec4a33633c8e8d9267dd014356cf857351c and fixed in 5.17.14 with commit e3a1ad8fd0ac11f4fa1260c23b5db71a25473254
Issue introduced in 4.3 with commit c7977ec4a33633c8e8d9267dd014356cf857351c and fixed in 5.18.3 with commit fb4f022b3ad1f3ff3cafdbc7d51896090ae17701
Issue introduced in 4.3 with commit c7977ec4a33633c8e8d9267dd014356cf857351c and fixed in 5.19 with commit 5376e3d904532e657fd7ca1a9b1ff3d351527b90
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2022-49445
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/pinctrl/renesas/core.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/f991879762392c19661af5b722578089a12b305f
https://git.kernel.org/stable/c/5ed0519d425619b435150372cce2ffeec71581fa
https://git.kernel.org/stable/c/e3a1ad8fd0ac11f4fa1260c23b5db71a25473254
https://git.kernel.org/stable/c/fb4f022b3ad1f3ff3cafdbc7d51896090ae17701
https://git.kernel.org/stable/c/5376e3d904532e657fd7ca1a9b1ff3d351527b90
Powered by blists - more mailing lists