CVE-2022-49445 Details
Description
In the Linux kernel, the following vulnerability has been resolved: pinctrl: renesas: core: Fix possible null-ptr-deref in sh_pfc_map_resources() It will cause null-ptr-deref when using 'res', if platform_get_resource() returns NULL, so move using 'res' after devm_ioremap_resource() that will check it to avoid null-ptr-deref. And use devm_platform_get_and_ioremap_resource() to simplify code.
A null pointer dereference vulnerability has been identified in the Linux kernel's pinctrl subsystem for Renesas platforms. The issue arises in the 'sh_pfc_map_resources()' function when 'platform_get_resource()' returns NULL. This can lead to a null pointer dereference when 'res' is used. The vulnerability has been addressed by modifying the code to use 'devm_ioremap_resource()' after checking the resource, thereby preventing the null pointer dereference. Additionally, 'devm_platform_get_and_ioremap_resource()' has been used to simplify the code.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/5376e3d904532e657fd7ca1a9b1ff3d351527b90 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5ed0519d425619b435150372cce2ffeec71581fa | kernel.org | Patch |
| https://git.kernel.org/stable/c/e3a1ad8fd0ac11f4fa1260c23b5db71a25473254 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f991879762392c19661af5b722578089a12b305f | kernel.org | Patch |
| https://git.kernel.org/stable/c/fb4f022b3ad1f3ff3cafdbc7d51896090ae17701 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.3, < 5.10.121 >= 5.11, < 5.15.46 >= 5.16, < 5.17.14 >= 5.18, < 5.18.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 1, 2025 | CVE Modified | CISA-ADP |
| Mar 17, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | kernel.org |