CVE-2022-49165

Source
https://cve.org/CVERecord?id=CVE-2022-49165
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49165.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49165
Downstream
Related
Published
2025-02-26T01:55:25.028Z
Modified
2026-03-20T12:22:13.410507Z
Summary
media: imx-jpeg: Prevent decoding NV12M jpegs into single-planar buffers
Details

In the Linux kernel, the following vulnerability has been resolved:

media: imx-jpeg: Prevent decoding NV12M jpegs into single-planar buffers

If the application queues an NV12M jpeg as output buffer, but then queues a single planar capture buffer, the kernel will crash with "Unable to handle kernel NULL pointer dereference" in mxcjpegaddrs, prevent this by finishing the job with error.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49165.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2db16c6ed72ce644d5639b3ed15e5817442db4ba
Fixed
eff76b180751e5e55c872d17755680c3b83ba9ab
Fixed
8d075ede7d24f19dc817c5bd517a53f0524f9031
Fixed
4eb591c47c82a6a6ad293ed108c3cb77115fbc25
Fixed
417591a766b3c040c346044541ff949c0b2bb7b2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49165.json"