NA

CVE-2022-3113

Published: 14/12/2022 Updated: 16/12/2022
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue exists in the Linux kernel up to and including 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 5.16.0

linux linux kernel

Vendor Advisories

Description<!----> This CVE is under investigation by Red Hat Product Security ...
Check Point Reference: CPAI-2022-1114 Date Published: 23 Jan 2023 Severity: Critical ...

Exploits

This Metasploit module exploits an unauthenticated command injection vulnerability in Roxy-WI versions prior to 6110 Successful exploitation results in remote code execution under the context of the web server user Roxy-WI is an interface for managing HAProxy, Nginx and Keepalived servers ...