SB20250226460 - NULL pointer dereference in Linux kernel clk driver
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2022-49187)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the clk_hw_create_clk() function in drivers/clk/clk.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0c1b56df451716ba207bbf59f303473643eee4fd
- https://git.kernel.org/stable/c/23f89fe005b105f0dcc55034c13eb89f9b570fac
- https://git.kernel.org/stable/c/4be3e4c05d8dd1b83b75652cad88c9e752ec7054
- https://git.kernel.org/stable/c/d183f20cf5a7b546d4108e796b98210ceb317579
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.19