UBUNTU-CVE-2022-48703

    Dashboard / Vulnerabilities / UBUNTU-CVE-2022-48703

    UBUNTU-CVE-2022-48703

    Published: 3 May 2024Last Modified: 9 Sept 2026
    Upstream:
    Aliases:

    Summary:

    Details: In the Linux kernel, the following vulnerability has been resolved: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR In some case, the GDDV returns a package with a buffer which has zero length. It causes that kmemdup() returns ZERO_SIZE_PTR (0x10). Then the data_vault_read() got NULL point dereference problem when accessing the 0x10 value in data_vault. [ 71.024560] BUG: kernel NULL pointer dereference, address: 0000000000000010 This patch uses ZERO_OR_NULL_PTR() for checking ZERO_SIZE_PTR or NULL value in data_vault.

    Affected packages

    Package

    Name: linux

    Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    3.11.0-12.19

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2022-48703 | CVE-DB