CVE-2023-52850
In the Linux kernel, the following vulnerability has been resolved: media: hantro: Check whether reset op is defined before use The i.MX8MM/N/P does not define the .reset op since reset of the VPU is done by genpd.
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: media: hantro: Check whether reset op is defined before use The i.MX8MM/N/P does not define the .reset op since reset of the VPU is done by genpd. Check whether the .reset op is defined before calling it to avoid NULL pointer dereference. Note that the Fixes tag is set to the commit which removed the reset op from i.MX8M Hantro G2 implementation, this is because before this commit all the implementations did define the .reset op.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/24c06295f28335ced3aad53dd4b0a0bae7b9b100Patch
- https://git.kernel.org/stable/c/64f55cebb4339ae771e9e7f3f42bee2489e2fa00Patch
- https://git.kernel.org/stable/c/66b4c5f980d741f3a47e4b65eeaf2797f2d59294Patch
- https://git.kernel.org/stable/c/88d4b23a629ebd34f682f770cb6c2116c851f7b8Patch
- https://git.kernel.org/stable/c/24c06295f28335ced3aad53dd4b0a0bae7b9b100Patch
- https://git.kernel.org/stable/c/64f55cebb4339ae771e9e7f3f42bee2489e2fa00Patch
- https://git.kernel.org/stable/c/66b4c5f980d741f3a47e4b65eeaf2797f2d59294Patch
- https://git.kernel.org/stable/c/88d4b23a629ebd34f682f770cb6c2116c851f7b8Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.