CVE-2022-49756 Information

Description

In the Linux kernel the following vulnerability has been resolved:

phy: usb: sunplus: Fix potential null-ptr-deref in sp_usb_phy_probe()

sp_usb_phy_probe() will call platform_get_resource_byname() that may fail and return NULL. devm_ioremap() will use usbphy->moon4_res_mem->start as input which may causes null-ptr-deref. Check the ret value of platform_get_resource_byname() to avoid the null-ptr-deref.

Reference

https://git.kernel.org/stable/c/17eee264ef386ef30a69dd70e36f29893b85c170 https://git.kernel.org/stable/c/d838b5c99bcecd593b4710a93fce8fdbf122395b

Share on: