
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in the Linux kernel through version 5.16-rc6, identified as CVE-2022-3115. The issue resides in the malidp_crtc_reset function within drivers/gpu/drm/arm/malidp_crtc.c, where it fails to check the return value of kzalloc(), potentially leading to a null pointer dereference (NVD, CVE).
The vulnerability is classified as a NULL Pointer Dereference (CWE-476) with a CVSS v3.1 base score of 5.5 (Medium). The issue specifically occurs in the ARM Mali display processor driver where the malidp_crtc_reset function fails to validate the return value of a memory allocation function, which could result in dereferencing a null pointer (NVD, Kernel Commit).
The vulnerability affects system availability by potentially causing a null pointer dereference, which could lead to a system crash or denial of service condition on affected Linux systems running the vulnerable kernel versions (NVD).
The vulnerability requires local access with low privileges and no user interaction to exploit. The attack complexity is considered low, making it relatively straightforward to trigger the vulnerability (NVD).
The vulnerability was fixed in Linux kernel 5.19-rc1 with a patch that adds proper return value checking for the kzalloc() function. The fix was implemented through commit 73c3ed7495c67b8fbdc31cf58e6ca8757df31a33 (Kernel Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."