SB20251230243 - NULL pointer dereference in Linux kernel media ipu3 driver
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2022-50826)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the imgu_subdev_set_fmt(), imgu_subdev_get_selection() and imgu_subdev_set_selection() functions in drivers/staging/media/ipu3/ipu3-v4l2.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5038ee677606106c91564f9c4557d808d14bad70
- https://git.kernel.org/stable/c/611d617bdb6c5d636a9861ec1c98e813fc8a5556
- https://git.kernel.org/stable/c/dc608edf7d45ba0c2ad14c06eccd66474fec7847
- https://git.kernel.org/stable/c/fa6bbb4894b9b947063c6ff90018a954c5f9f4b3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.87