CVE-2022-49319

Modified
Published: 26 Feb 2025, 02:10
Last modified:11 May 2026, 18:57

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.1% LOW
0% probability +0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Feb 2025, 02:10
Published
Vulnerability first disclosed
11 May 2026, 18:57
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.10% Percentile: 28%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • linuxlinux

    ≥ 48ec83bcbcf5090fcdf74a6168f161d247492979, < 54c1e0e3bbcab2abe25b2874a43050ae5df87831 | ≥ 48ec83bcbcf5090fcdf74a6168f161d247492979, < fb0f1c5eb8d60b3e018ba7c87da249b52674ebe6 | ≥ 48ec83bcbcf5090fcdf74a6168f161d247492979, < db728a891f9177b044aaca89b678f6b5e24d5cc3 | ≥ 48ec83bcbcf5090fcdf74a6168f161d247492979, < 54cf47da0c7532d151d76e5d63f5936191698c44 | ≥ 48ec83bcbcf5090fcdf74a6168f161d247492979, < b131fa8c1d2afd05d0b7598621114674289c2fbb | 4.2

  • linuxlinux_kernel

    < 5.10.122 | ≥ 5.11, < 5.15.47 | ≥ 5.16, < 5.17.15 | ≥ 5.18, < 5.18.4

References (5)