From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 06AEB2165EC for ; Wed, 26 Feb 2025 02:14:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740536046; cv=none; b=MpRaq319dDbxP/vxb9FzHuFqRrctk9IwZfTAHBlef40kyAUbW5zMQHaEp/leHwLr2nbM/Hvdiw7meWcHFid4PewzJJ46zi5uvOhbeM9PFYoaVtNb7VIF/l35YeFhzsD94/6v5vvC1bj8Et5g43Q4vrg1QqRz7SPkdsYuvJwoUrQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740536046; c=relaxed/simple; bh=xjx5UIGgZLlUcc7fEELHPRlrjq2F6BI45v9Y2daCHhg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=hJYJgUzKcdmdG8ECc4SF1cxFrWzoIqJdee78Welf2RRDXzAP5GQzefc5q/AlePtEm5SiM0ZBf9738fqdXW3Jem8kpm02lharmwMVAATpLLLo7zfahiSiptq2S3jjlXk1NkJlQlQ/qXPL9g0eyT72XiNn29j58LOQV1p6ftzymZs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=KqlZKjxv; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="KqlZKjxv" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CD250C4CEDD; Wed, 26 Feb 2025 02:14:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1740536045; bh=xjx5UIGgZLlUcc7fEELHPRlrjq2F6BI45v9Y2daCHhg=; h=From:To:Cc:Subject:Date:Reply-to:From; b=KqlZKjxvViZEn7H/IZjIgEZ34BrRnZKd7RzlyL4Aku7COl6nCA8Bo5u0ZglGMbg3j 0v9aBr3oWYr0h7LF75KM06NJfozLCtOpQITAsmMQ5MVOS0d2hSyDCHxXe2Pr35uRP2 FVyR6cZCvrBl2OxPAVIz+Au4V3AHFtprHalgOLtY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2022-49417: iwlwifi: mei: fix potential NULL-ptr deref Date: Wed, 26 Feb 2025 03:11:31 +0100 Message-ID: <2025022653-CVE-2022-49417-2a5f@gregkh> X-Mailer: git-send-email 2.48.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=2095; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=xjx5UIGgZLlUcc7fEELHPRlrjq2F6BI45v9Y2daCHhg=; b=owGbwMvMwCRo6H6F97bub03G02pJDOn7yj8yMhY+nJUxv0CTbXP1r8aVx9v2TvohEZQ/KapT+ qVn+qTGjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZhIxnuG+ZkV92YyG0/MPPm9 4n0xu/TdtjdHZBjmmb48XbeRMT7cdunBK0//KxjdNn+1DAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: iwlwifi: mei: fix potential NULL-ptr deref If SKB allocation fails, continue rather than using the NULL pointer. Coverity CID: 1497650 The Linux kernel CVE team has assigned CVE-2022-49417 to this issue. Affected and fixed versions =========================== Issue introduced in 5.17 with commit 2da4366f9e2c44afedec4acad65a99a3c7da1a35 and fixed in 5.17.14 with commit 29b81de94d62b5e2704bb5106b3e701ca8d7c7a4 Issue introduced in 5.17 with commit 2da4366f9e2c44afedec4acad65a99a3c7da1a35 and fixed in 5.18.3 with commit 5d8d06fd3a02919100b28f927bcb76481ec0a0e3 Issue introduced in 5.17 with commit 2da4366f9e2c44afedec4acad65a99a3c7da1a35 and fixed in 5.19 with commit 78488a64aea94a3336ee97f345c1496e9bc5ebdf Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2022-49417 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/wireless/intel/iwlwifi/mei/main.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/29b81de94d62b5e2704bb5106b3e701ca8d7c7a4 https://git.kernel.org/stable/c/5d8d06fd3a02919100b28f927bcb76481ec0a0e3 https://git.kernel.org/stable/c/78488a64aea94a3336ee97f345c1496e9bc5ebdf