CVE-2022-49494

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-49494
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49494.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49494
Downstream
Related
Published
2025-02-26T02:13:30Z
Modified
2025-10-21T10:45:28.989610Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
mtd: rawnand: cadence: fix possible null-ptr-deref in cadence_nand_dt_probe()
Details

In the Linux kernel, the following vulnerability has been resolved:

mtd: rawnand: cadence: fix possible null-ptr-deref in cadencenanddt_probe()

It will cause null-ptr-deref when using 'res', if platformgetresource() returns NULL, so move using 'res' after devmioremapresource() that will check it to avoid null-ptr-deref. And use devmplatformgetandioremap_resource() to simplify code.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ec4ba01e894d3165e4d1ccbef782ef5593b708b4
Fixed
81f1ddffdc22ca5789e33b9d4712914e302090c1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ec4ba01e894d3165e4d1ccbef782ef5593b708b4
Fixed
0cfee868b89ffa945f3d535ee5c985cb40c5a0f8
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ec4ba01e894d3165e4d1ccbef782ef5593b708b4
Fixed
069af5e27c1b0f7677ef76d8d3102e503ca4f80b
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ec4ba01e894d3165e4d1ccbef782ef5593b708b4
Fixed
13b60d3dc84b47307669edb66b633b18466014b4
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ec4ba01e894d3165e4d1ccbef782ef5593b708b4
Fixed
a28ed09dafee20da51eb26452950839633afd824

Affected versions

v5.*

v5.10
v5.10-rc1
v5.10-rc2
v5.10-rc3
v5.10-rc4
v5.10-rc5
v5.10-rc6
v5.10-rc7
v5.10.1
v5.10.10
v5.10.100
v5.10.101
v5.10.102
v5.10.103
v5.10.104
v5.10.105
v5.10.106
v5.10.107
v5.10.108
v5.10.109
v5.10.11
v5.10.110
v5.10.111
v5.10.112
v5.10.113
v5.10.114
v5.10.115
v5.10.116
v5.10.117
v5.10.118
v5.10.119
v5.10.12
v5.10.120
v5.10.13
v5.10.14
v5.10.15
v5.10.16
v5.10.17
v5.10.18
v5.10.19
v5.10.2
v5.10.20
v5.10.21
v5.10.22
v5.10.23
v5.10.24
v5.10.25
v5.10.26
v5.10.27
v5.10.28
v5.10.29
v5.10.3
v5.10.30
v5.10.31
v5.10.32
v5.10.33
v5.10.34
v5.10.35
v5.10.36
v5.10.37
v5.10.38
v5.10.39
v5.10.4
v5.10.40
v5.10.41
v5.10.42
v5.10.43
v5.10.44
v5.10.45
v5.10.46
v5.10.47
v5.10.48
v5.10.49
v5.10.5
v5.10.50
v5.10.51
v5.10.52
v5.10.53
v5.10.54
v5.10.55
v5.10.56
v5.10.57
v5.10.58
v5.10.59
v5.10.6
v5.10.60
v5.10.61
v5.10.62
v5.10.63
v5.10.64
v5.10.65
v5.10.66
v5.10.67
v5.10.68
v5.10.69
v5.10.7
v5.10.70
v5.10.71
v5.10.72
v5.10.73
v5.10.74
v5.10.75
v5.10.76
v5.10.77
v5.10.78
v5.10.79
v5.10.8
v5.10.80
v5.10.81
v5.10.82
v5.10.83
v5.10.84
v5.10.85
v5.10.86
v5.10.87
v5.10.88
v5.10.89
v5.10.9
v5.10.90
v5.10.91
v5.10.92
v5.10.93
v5.10.94
v5.10.95
v5.10.96
v5.10.97
v5.10.98
v5.10.99
v5.11
v5.11-rc1
v5.11-rc2
v5.11-rc3
v5.11-rc4
v5.11-rc5
v5.11-rc6
v5.11-rc7
v5.12
v5.12-rc1
v5.12-rc1-dontuse
v5.12-rc2
v5.12-rc3
v5.12-rc4
v5.12-rc5
v5.12-rc6
v5.12-rc7
v5.12-rc8
v5.13
v5.13-rc1
v5.13-rc2
v5.13-rc3
v5.13-rc4
v5.13-rc5
v5.13-rc6
v5.13-rc7
v5.14
v5.14-rc1
v5.14-rc2
v5.14-rc3
v5.14-rc4
v5.14-rc5
v5.14-rc6
v5.14-rc7
v5.15
v5.15-rc1
v5.15-rc2
v5.15-rc3
v5.15-rc4
v5.15-rc5
v5.15-rc6
v5.15-rc7
v5.15.1
v5.15.10
v5.15.11
v5.15.12
v5.15.13
v5.15.14
v5.15.15
v5.15.16
v5.15.17
v5.15.18
v5.15.19
v5.15.2
v5.15.20
v5.15.21
v5.15.22
v5.15.23
v5.15.24
v5.15.25
v5.15.26
v5.15.27
v5.15.28
v5.15.29
v5.15.3
v5.15.30
v5.15.31
v5.15.32
v5.15.33
v5.15.34
v5.15.35
v5.15.36
v5.15.37
v5.15.38
v5.15.39
v5.15.4
v5.15.40
v5.15.41
v5.15.42
v5.15.43
v5.15.44
v5.15.45
v5.15.5
v5.15.6
v5.15.7
v5.15.8
v5.15.9
v5.16
v5.16-rc1
v5.16-rc2
v5.16-rc3
v5.16-rc4
v5.16-rc5
v5.16-rc6
v5.16-rc7
v5.16-rc8
v5.17
v5.17-rc1
v5.17-rc2
v5.17-rc3
v5.17-rc4
v5.17-rc5
v5.17-rc6
v5.17-rc7
v5.17-rc8
v5.17.1
v5.17.10
v5.17.11
v5.17.12
v5.17.13
v5.17.2
v5.17.3
v5.17.4
v5.17.5
v5.17.6
v5.17.7
v5.17.8
v5.17.9
v5.18
v5.18-rc1
v5.18-rc2
v5.18-rc3
v5.18-rc4
v5.18-rc5
v5.18-rc6
v5.18-rc7
v5.18.1
v5.18.2
v5.4
v5.4-rc2
v5.4-rc3
v5.4-rc4
v5.4-rc5
v5.4-rc6
v5.4-rc7
v5.4-rc8
v5.5
v5.5-rc1
v5.5-rc2
v5.5-rc3
v5.5-rc4
v5.5-rc5
v5.5-rc6
v5.5-rc7
v5.6
v5.6-rc1
v5.6-rc2
v5.6-rc3
v5.6-rc4
v5.6-rc5
v5.6-rc6
v5.6-rc7
v5.7
v5.7-rc1
v5.7-rc2
v5.7-rc3
v5.7-rc4
v5.7-rc5
v5.7-rc6
v5.7-rc7
v5.8
v5.8-rc1
v5.8-rc2
v5.8-rc3
v5.8-rc4
v5.8-rc5
v5.8-rc6
v5.8-rc7
v5.9
v5.9-rc1
v5.9-rc2
v5.9-rc3
v5.9-rc4
v5.9-rc5
v5.9-rc6
v5.9-rc7
v5.9-rc8

Database specific

vanir_signatures

[
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@069af5e27c1b0f7677ef76d8d3102e503ca4f80b",
        "target": {
            "function": "cadence_nand_dt_probe",
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "digest": {
            "function_hash": "142786640517340535029077624318549955276",
            "length": 1445.0
        },
        "id": "CVE-2022-49494-11b400c8"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@81f1ddffdc22ca5789e33b9d4712914e302090c1",
        "target": {
            "function": "cadence_nand_dt_probe",
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "digest": {
            "function_hash": "142786640517340535029077624318549955276",
            "length": 1445.0
        },
        "id": "CVE-2022-49494-1ab87646"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@81f1ddffdc22ca5789e33b9d4712914e302090c1",
        "target": {
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "269390356367171351878066556557259625098",
                "315562494251448214947174642054996044918",
                "231335816417077177123968638593060342107",
                "304220219225402584960559059722963330669",
                "133342046802052494434211178795059059644",
                "285874294398958309225633323825693355698",
                "333513254756247381206286297485342343889",
                "202704142252856435041202763192081722890"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-49494-2a4c6be0"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0cfee868b89ffa945f3d535ee5c985cb40c5a0f8",
        "target": {
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "269390356367171351878066556557259625098",
                "315562494251448214947174642054996044918",
                "231335816417077177123968638593060342107",
                "304220219225402584960559059722963330669",
                "133342046802052494434211178795059059644",
                "285874294398958309225633323825693355698",
                "333513254756247381206286297485342343889",
                "202704142252856435041202763192081722890"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-49494-517af488"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a28ed09dafee20da51eb26452950839633afd824",
        "target": {
            "function": "cadence_nand_dt_probe",
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "digest": {
            "function_hash": "142786640517340535029077624318549955276",
            "length": 1445.0
        },
        "id": "CVE-2022-49494-734364ba"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@13b60d3dc84b47307669edb66b633b18466014b4",
        "target": {
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "269390356367171351878066556557259625098",
                "315562494251448214947174642054996044918",
                "231335816417077177123968638593060342107",
                "304220219225402584960559059722963330669",
                "133342046802052494434211178795059059644",
                "285874294398958309225633323825693355698",
                "333513254756247381206286297485342343889",
                "202704142252856435041202763192081722890"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-49494-91376f9e"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@069af5e27c1b0f7677ef76d8d3102e503ca4f80b",
        "target": {
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "269390356367171351878066556557259625098",
                "315562494251448214947174642054996044918",
                "231335816417077177123968638593060342107",
                "304220219225402584960559059722963330669",
                "133342046802052494434211178795059059644",
                "285874294398958309225633323825693355698",
                "333513254756247381206286297485342343889",
                "202704142252856435041202763192081722890"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-49494-9a24eb0f"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0cfee868b89ffa945f3d535ee5c985cb40c5a0f8",
        "target": {
            "function": "cadence_nand_dt_probe",
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "digest": {
            "function_hash": "142786640517340535029077624318549955276",
            "length": 1445.0
        },
        "id": "CVE-2022-49494-aa62ea27"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@13b60d3dc84b47307669edb66b633b18466014b4",
        "target": {
            "function": "cadence_nand_dt_probe",
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function",
        "digest": {
            "function_hash": "142786640517340535029077624318549955276",
            "length": 1445.0
        },
        "id": "CVE-2022-49494-beb9b7e5"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a28ed09dafee20da51eb26452950839633afd824",
        "target": {
            "file": "drivers/mtd/nand/raw/cadence-nand-controller.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "269390356367171351878066556557259625098",
                "315562494251448214947174642054996044918",
                "231335816417077177123968638593060342107",
                "304220219225402584960559059722963330669",
                "133342046802052494434211178795059059644",
                "285874294398958309225633323825693355698",
                "333513254756247381206286297485342343889",
                "202704142252856435041202763192081722890"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-49494-f8ce55bf"
    }
]

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.121
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.46
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.17.14
Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
5.18.3