-

CVE-2022-50276

In the Linux kernel, the following vulnerability has been resolved:

power: supply: fix null pointer dereferencing in power_supply_get_battery_info

when kmalloc() fail to allocate memory in kasprintf(), propname
will be NULL, strcmp() called by of_get_property() will cause
null pointer dereference.

So return ENOMEM if kasprintf() return NULL pointer.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 8ea68b4e3fa9392ef9dae303abc8735a033c280f
Version 3afb50d7125bcdbf71df843134e96ceffc78c8b8
Status affected
Version < 5beadb55f4e36fafe5d6df5dcd5f85d803f3f134
Version 3afb50d7125bcdbf71df843134e96ceffc78c8b8
Status affected
Version < d21534ab4fd7883e1c8037a76671d4e8b6ea14cb
Version 3afb50d7125bcdbf71df843134e96ceffc78c8b8
Status affected
Version < 279af90e65cbdb3e5c4519b0043324d7876bc5ec
Version 3afb50d7125bcdbf71df843134e96ceffc78c8b8
Status affected
Version < b8131efb89d9f837c9244f900f0fc2699fd1181d
Version 3afb50d7125bcdbf71df843134e96ceffc78c8b8
Status affected
Version < 104bb8a663451404a26331263ce5b96c34504049
Version 3afb50d7125bcdbf71df843134e96ceffc78c8b8
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.0
Status affected
Version < 5.0
Version 0
Status unaffected
Version <= 5.4.*
Version 5.4.229
Status unaffected
Version <= 5.10.*
Version 5.10.163
Status unaffected
Version <= 5.15.*
Version 5.15.86
Status unaffected
Version <= 6.0.*
Version 6.0.16
Status unaffected
Version <= 6.1.*
Version 6.1.2
Status unaffected
Version <= *
Version 6.2
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.125
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string