SB20250226387 - NULL pointer dereference in Linux kernel iommu driver
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2022-49424)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the MT2701_IOMMU_PAGE_SIZE() and mtk_iommu_probe_device() functions in drivers/iommu/mtk_iommu_v1.c, within the mtk_iommu_probe_device() function in drivers/iommu/mtk_iommu.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/8837c2682b9b2eed83e6212bcf79850c593a6fee
- https://git.kernel.org/stable/c/c3c2734e28d7fac50228c4d2b8896e8695adf304
- https://git.kernel.org/stable/c/de78657e16f41417da9332f09c2d67d100096939
- https://git.kernel.org/stable/c/e9c63c0f73a1bbfd02624f5eae7e881df8b6830f
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.14