CVE-2022-49010
Published: Oct 21, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Check for null before removing sysfs attrs If coretemp_add_core() gets an error then pdata->core_data[indx] is already NULL and has been kfreed. Don't pass that to sysfs_remove_group() as that will crash in sysfs_remove_group(). [Shortened for readability] [91854.020159] sysfs: cannot create duplicate filename '/devices/platform/coretemp.0/hwmon/hwmon2/temp20_label' <cpu offline> [91855.126115] BUG: kernel NULL pointer dereference, address: 0000000000000188 [91855.165103] #PF: supervisor read access in kernel mode [91855.194506] #PF: error_code(0x0000) - not-present page [91855.224445] PGD 0 P4D 0 [91855.238508] Oops: 0000 [#1] PREEMPT SMP PTI ... [91855.342716] RIP: 0010:sysfs_remove_group+0xc/0x80 ... [91855.796571] Call Trace: [91855.810524] coretemp_cpu_offline+0x12b/0x1dd [coretemp] [91855.841738] ? coretemp_cpu_online+0x180/0x180 [coretemp] [91855.871107] cpuhp_invoke_callback+0x105/0x4b0 [91855.893432] cpuhp_thread_fun+0x8e/0x150 ... Fix this by checking for NULL first.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 199e0de7f5df31a4fc485d4aaaf8a07718252ace - < fb503d077ff7b43913503eaf72995d1239028b99affected 199e0de7f5df31a4fc485d4aaaf8a07718252ace - < 070d5ea4a0592a37ad96ce7f7b6b024f90bb009faffected 199e0de7f5df31a4fc485d4aaaf8a07718252ace - < 280110db1a7d62ad635b103bafc3ae96e8bef75caffected 199e0de7f5df31a4fc485d4aaaf8a07718252ace - < 89eecabe6a47403237f45aafd7d24f93cb973653affected 199e0de7f5df31a4fc485d4aaaf8a07718252ace - < f06e0cd01eab954bd5f2190c9faa79bb5357e05b+3 more versions |
Linux | Linux | affected 3.0unaffected 0 - < 3.0unaffected 4.9.335 - <= 4.9.*unaffected 4.14.301 - <= 4.14.*unaffected 4.19.268 - <= 4.19.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now