CVE-2022-48879: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: efi: fix NULL-deref in init error path In cases where runtime services are not supported or have been disabled, the runtime services workqueue will never have been allocated. Do not try to destroy the workqueue unconditionally in the unlikely event that EFI initialisation fails to avoid dereferencing a NULL pointer.

Affected products

  • Linux Linux Kernel: from 4.19.142, before 4.19.270 (fixed in 4.19.270); from 5.4.61, before 5.4.229 (fixed in 5.4.229); from 5.9, before 5.10.164 (fixed in 5.10.164); from 5.11, before 5.15.89 (fixed in 5.15.89); from 5.16, before 6.1.7 (fixed in 6.1.7)

Published 2024-08-21. Last modified 2026-06-17.