CVE-2022-50415
18.09.2025, 16:15
In the Linux kernel, the following vulnerability has been resolved:
parisc: led: Fix potential null-ptr-deref in start_task()
start_task() calls create_singlethread_workqueue() and not checked the
ret value, which may return NULL. And a null-ptr-deref may happen:
start_task()
create_singlethread_workqueue() # failed, led_wq is NULL
queue_delayed_work()
queue_delayed_work_on()
__queue_delayed_work() # warning here, but continue
__queue_work() # access wq->flags, null-ptr-deref
Check the ret value and return -ENOMEM if it is NULL.Enginsight| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 2.6.15 ≤ 𝑥 < 4.9.337 |
| linux | linux_kernel | 4.10 ≤ 𝑥 < 4.14.303 |
| linux | linux_kernel | 4.15 ≤ 𝑥 < 4.19.270 |
| linux | linux_kernel | 4.20 ≤ 𝑥 < 5.4.229 |
| linux | linux_kernel | 5.5 ≤ 𝑥 < 5.10.163 |
| linux | linux_kernel | 5.11 ≤ 𝑥 < 5.15.87 |
| linux | linux_kernel | 5.16 ≤ 𝑥 < 6.0.18 |
| linux | linux_kernel | 6.1 ≤ 𝑥 < 6.1.4 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
References