PT-2022-7621 · Linux+2 · Linux Kernel+2

Zheyu Ma

·

Published

2022-03-03

·

Updated

2025-10-01

·

CVE-2022-48908

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fix in commit 5f394102ee27dbf05la4e283390cd8d1759dacea
Description The vulnerability is related to a null pointer dereference in the com20020pci probe() function during driver initialization. The issue arises because the com20020pci id table definition reveals that the ci field is empty for some devices, causing a null pointer dereference when initializing these devices. This can lead to a denial of service. The vulnerability affects all versions of the Linux kernel prior to the fix.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix, specifically to a version after the commit 5f394102ee27dbf05la4e283390cd8d1759dacea. As a temporary workaround, consider disabling the com20020pci probe() function until a patch is available. However, this may have implications for the functionality of the affected devices.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-07465
CVE-2022-48908
OESA-2024-2109

Affected Products

Astra Linux
Linux Kernel
Red Os