CVE-2022-49499
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49499 is a vulnerability in the Linux kernel's DRM/MSM (Direct Rendering Manager for Qualcomm Snapdragon) component. The vulnerability was disclosed on February 26, 2025, and involves potential null pointer dereferences in situations where IOMMU is not present. Specifically, the issue affects systems using MSM8974 chipsets where the 'aspace' pointer can remain null without IOMMU (Kernel Git).

Technical details

The vulnerability stems from a failure to check if the 'aspace' pointer is set before using it in the DRM/MSM driver. This condition occurs specifically when IOMMU (Input-Output Memory Management Unit) is not present in the system. The issue was introduced in commit bc2112583a0b ("drm/msm/gpu: Track global faults per address-space") and was fixed by adding proper null pointer checks before accessing the 'aspace' member (Kernel Git).

Impact

When triggered, this vulnerability can lead to null pointer dereferences in the Linux kernel's DRM/MSM driver, potentially causing system crashes or denial of service conditions on affected systems, particularly those using MSM8974 chipsets without IOMMU (Kernel Git).

Mitigation and workarounds

The vulnerability has been fixed by adding proper null pointer checks before accessing the 'aspace' member. The fix was implemented in two kernel commits that modify the affected files (drivers/gpu/drm/msm/adreno/adrenogpu.c and drivers/gpu/drm/msm/msmgpu.c) to properly handle cases where 'aspace' is null (Kernel Git).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management