CVE-2022-49984

Source
https://cve.org/CVERecord?id=CVE-2022-49984
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49984.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49984
Downstream
Related
Published
2025-06-18T11:00:46.543Z
Modified
2026-04-11T12:44:45.945777Z
Summary
HID: steam: Prevent NULL pointer dereference in steam_{recv,send}_report
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: steam: Prevent NULL pointer dereference in steam_{recv,send}_report

It is possible for a malicious device to forgo submitting a Feature Report. The HID Steam driver presently makes no prevision for this and de-references the 'struct hid_report' pointer obtained from the HID devices without first checking its validity. Let's change that.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49984.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c164d6abf3841ffacfdb757c10616f9cb1f67276
Fixed
c20d03b82a2e3ddbb555dad4d4f3374a9763222c
Fixed
fa2b822d86be5b5ad54fe4fa2daca464e71ff90a
Fixed
dc815761948ab5b8c94db6cb53c95103588f16ae
Fixed
989560b6d9e00d99e07bc33067fa1c770994bf4d
Fixed
dee1e51b54794e90763e70a3c78f27ba4fa930ec
Fixed
cd11d1a6114bd4bc6450ae59f6e110ec47362126

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49984.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.18.0
Fixed
4.19.257
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.212
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.141
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.65
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.19.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49984.json"