CVE-2022-49046: i2c: dev: check return value when calling dev_set_name()
Published Feb 26, 2025
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
11 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=4.4.225<4.5
Linux Linux kernel>=4.9.225<4.10
Linux Linux kernel>=4.14.182<4.15
Linux Linux kernel>=4.19.125<4.20
Linux Linux kernel>=5.4.43<5.5
Linux Linux kernel>=5.6.15<5.15.35
Linux Linux kernel>=5.16<5.17.4
Linux Linux kernel=5.18-rc1
Linux Linux kernel=5.18-rc2
debian/linux<=5.10.223-1
5.10.251-46.1.159-16.1.170-36.12.73-16.12.86-17.0.4-1
Remediation
Event History
Feb 26, 2025
CVE Published
via MITRE·01:54 AM
Data Sourced
via MITRE·01:54 AM
Description
Data Sourced
via NVD·07:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 13, 2026
Data Sourced
via Debian·04:06 AM
DescriptionAffected Software
Data Sourced
via Launchpad·04:06 AM
Description
May 14, 2026
Data Sourced
via Ubuntu·04:06 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-49046?
CVE-2022-49046 has been rated with a moderate severity level due to potential null pointer dereference risks in the Linux kernel.
2
How do I fix CVE-2022-49046?
To fix CVE-2022-49046, ensure that you upgrade to the latest Linux kernel version where the vulnerability has been patched.
3
Which versions of the Linux kernel are affected by CVE-2022-49046?
CVE-2022-49046 affects Linux kernel versions from 4.4.225 to 5.18-rc2.
4
What does CVE-2022-49046 vulnerability entail?
CVE-2022-49046 relates to a failure in the i2c device subsystem where the return value of dev_set_name() wasn't checked, which could lead to null pointer dereference.
5
Is CVE-2022-49046 actively being exploited?
As of now, there is no information indicating that CVE-2022-49046 is actively being exploited in the wild.