๐Ÿ” CVE Alert

CVE-2022-48908

MEDIUM 5.5

net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe() During driver initialization, the pointer of card info, i.e. the variable 'ci' is required. However, the definition of 'com20020pci_id_table' reveals that this field is empty for some devices, which will cause null pointer dereference when initializing these devices. The following log reveals it: [ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f] [ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci] [ 3.975181] Call Trace: [ 3.976208] local_pci_probe+0x13f/0x210 [ 3.977248] pci_device_probe+0x34c/0x6d0 [ 3.977255] ? pci_uevent+0x470/0x470 [ 3.978265] really_probe+0x24c/0x8d0 [ 3.978273] __driver_probe_device+0x1b3/0x280 [ 3.979288] driver_probe_device+0x50/0x370 Fix this by checking whether the 'ci' is a null pointer first.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 22, 2024
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new medium vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < 8e3bc7c5bbf87e86e9cd652ca2a9166942d86206 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < b1ee6b9340a38bdb9e5c90f0eac5b22b122c3049 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < b838add93e1dd98210482dc433768daaf752bdef 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < e50c589678e50f8d574612e473ca60ef45190896 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < 5f394102ee27dbf051a4e283390cd8d1759dacea 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < ea372aab54903310756217d81610901a8e66cb7d 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < ca0bdff4249a644f2ca7a49d410d95b8dacf1f72 8c14f9c70327a6fb75534c4c61d7ea9c82ccf78f < bd6f1fd5d33dfe5d1b4f2502d3694a7cc13f166d
Linux / Linux
3.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/8e3bc7c5bbf87e86e9cd652ca2a9166942d86206 git.kernel.org: https://git.kernel.org/stable/c/b1ee6b9340a38bdb9e5c90f0eac5b22b122c3049 git.kernel.org: https://git.kernel.org/stable/c/b838add93e1dd98210482dc433768daaf752bdef git.kernel.org: https://git.kernel.org/stable/c/e50c589678e50f8d574612e473ca60ef45190896 git.kernel.org: https://git.kernel.org/stable/c/5f394102ee27dbf051a4e283390cd8d1759dacea git.kernel.org: https://git.kernel.org/stable/c/ea372aab54903310756217d81610901a8e66cb7d git.kernel.org: https://git.kernel.org/stable/c/ca0bdff4249a644f2ca7a49d410d95b8dacf1f72 git.kernel.org: https://git.kernel.org/stable/c/bd6f1fd5d33dfe5d1b4f2502d3694a7cc13f166d