CVE-2022-49608: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: pinctrl: ralink: Check for null return of devm_kcalloc Because of the possible failure of the allocation, data->domains might be NULL pointer and will cause the dereference of the NULL pointer later. Therefore, it might be better to check it and directly return -ENOMEM without releasing data manually if fails, because the comment of the devm_kmalloc() says "Memory allocated with this function is automatically freed on driver detach.".

Affected products

  • Linux Linux Kernel: from 4.18, before 4.19.254 (fixed in 4.19.254); from 4.20, before 5.4.208 (fixed in 5.4.208); from 5.5, before 5.10.134 (fixed in 5.10.134); from 5.11, before 5.15.58 (fixed in 5.15.58); from 5.16, before 5.18.15 (fixed in 5.18.15); version 5.19 only

Published 2025-02-26. Last modified 2026-06-17.