CVE-2022-50272 Details
Description
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer() Wei Chen reports a kernel bug as blew: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] ... Call Trace: <TASK> __i2c_transfer+0x77e/0x1930 drivers/i2c/i2c-core-base.c:2109 i2c_transfer+0x1d5/0x3d0 drivers/i2c/i2c-core-base.c:2170 i2cdev_ioctl_rdwr+0x393/0x660 drivers/i2c/i2c-dev.c:297 i2cdev_ioctl+0x75d/0x9f0 drivers/i2c/i2c-dev.c:458 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:870 [inline] __se_sys_ioctl+0xfb/0x170 fs/ioctl.c:856 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x3d/0x90 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd RIP: 0033:0x7fd834a8bded In az6027_i2c_xfer(), if msg[i].addr is 0x99, a null-ptr-deref will caused when accessing msg[i].buf. For msg[i].len is 0 and msg[i].buf is null. Fix this by checking msg[i].len in az6027_i2c_xfer().
A null pointer dereference vulnerability has been identified in the Linux kernel's AZ6027 DVB-USB driver. This issue occurs in the 'az6027_i2c_xfer()' function when the I2C message address is '0x99'. If the message length is zero, the buffer pointer is null, leading to a general protection fault. The vulnerability has been addressed by adding a check for the message length before accessing the buffer.
Users can upgrade to the patched version of the Linux kernel where this vulnerability has been fixed. The specific commit addressing this issue is '0ed554fd769a19ea8464bb83e9ac201002ef74ad', which is included in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0ed554fd769a19ea8464bb83e9ac201002ef74ad | kernel.org | Patch |
| https://git.kernel.org/stable/c/210fcf64be4db82c0e190e74b5111e4eef661a7a | kernel.org | Patch |
| https://git.kernel.org/stable/c/2b6a8a1a32746981044e7ab06649c804acb4068a | kernel.org | Patch |
| https://git.kernel.org/stable/c/559891d430e3f3a178040c4371ed419edbfa7d65 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6b60cf73a931af34b7a0a3f467a79d9fe0df2d70 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6fbc44731a4665cbe92a5090e9804a388a72214b | kernel.org | Patch |
| https://git.kernel.org/stable/c/7abfe467cd685f5da7ecb415441e45e3e4e2baa8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8b256d23361c51aa4b7fdb71176c1ca50966fb39 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c712d1ccbfb787620422b437a5b8fac0802547bd | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.34, < 4.9.337 >= 4.10, < 4.14.303 >= 4.15, < 4.19.270 >= 4.20, < 5.4.229 >= 5.5, < 5.10.163 >= 5.11, < 5.15.86 >= 5.16, < 6.0.16 >= 6.1, < 6.1.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 3, 2025 | Initial Analysis | [email protected] |
| Sep 15, 2025 | New CVE Received | kernel.org |