media: ipu3-imgu: Fix NULL pointer dereference in active selection access
Published Dec 24, 2025
No CVSS score
EPSS 0.24%
Description
What the IMGU driver did was that it first acquired the pointers to active and try V4L2 subdev state, and only then figured out which one to use.
The problem with that approach and a later patch (see Fixes: tag) is that as sd_state argument to v4l2_subdev_get_try_crop() et al is NULL, there is now an attempt to dereference that.
Fix this.
Also rewrap lines a little.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.14
- Version 5.15.76StatusunaffectedConstraints<=5.15.*
- Version 6.0.6StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-50722 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2425022 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55767 Advisory
- https://git.kernel.org/stable/c/5265cc1202a31f7097691c3483a0d60d624424a5
- https://git.kernel.org/stable/c/740717b756c17190dc2d2ad4c6de1e63f214e0c9
- https://git.kernel.org/stable/c/b9eb3ab6f30bf32f7326909f17949ccb11bab514
- https://lore.kernel.org/linux-cve-announce/2025122417-CVE-2022-50722-06c7@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50722
- https://www.cve.org/CVERecord?id=CVE-2022-50722
Change history (0)
No recorded changes yet.