CVE-2022-49832: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix null pointer dereferencing in pinctrl_dt_to_map Here is the BUG report by KASAN about null pointer dereference: BUG: KASAN: null-ptr-deref in strcmp+0x2e/0x50 Read of size 1 at addr 0000000000000000 by task python3/2640 Call Trace: strcmp __of_find_property of_find_property pinctrl_dt_to_map kasprintf() would return NULL pointer when kmalloc() fail to allocate. So directly return ENOMEM, if kasprintf() return NULL pointer.

Affected products

  • Linux Linux Kernel: from 3.5, before 4.9.334 (fixed in 4.9.334); from 4.10, before 4.14.300 (fixed in 4.14.300); from 4.15, before 4.19.267 (fixed in 4.19.267); from 4.20, before 5.4.225 (fixed in 5.4.225); from 5.5, before 5.10.156 (fixed in 5.10.156); from 5.11, before 5.15.80 (fixed in 5.15.80); …

Published 2025-05-01. Last modified 2026-06-17.