SB20251230239 - NULL pointer dereference in Linux kernel of driver
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2022-50875)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the find_dup_cset_node_entry() and find_dup_cset_prop() functions in drivers/of/overlay.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2b4af99b44861646013821019dd13a4ac48c0219
- https://git.kernel.org/stable/c/71d88c7453ec3d2ceff98e18ce4d6354abd3b5b6
- https://git.kernel.org/stable/c/9ec5781879b4535ad59b5354b385825378e45618
- https://git.kernel.org/stable/c/ab5bb7bbacf531de8e32912cc2e21f906113cee8
- https://git.kernel.org/stable/c/ce1b3a41e7964cb8dd56a702a95dd90ad27f51cd
- https://git.kernel.org/stable/c/ee9d7a0e754568180a2f8ebc4aad226278a9116f
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.163
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.86
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.229
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2