{"id":"CVE-2022-50722","summary":"media: ipu3-imgu: Fix NULL pointer dereference in active selection access","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ipu3-imgu: Fix NULL pointer dereference in active selection access\n\nWhat the IMGU driver did was that it first acquired the pointers to active\nand try V4L2 subdev state, and only then figured out which one to use.\n\nThe problem with that approach and a later patch (see Fixes: tag) is that\nas sd_state argument to v4l2_subdev_get_try_crop() et al is NULL, there is\nnow an attempt to dereference that.\n\nFix this.\n\nAlso rewrap lines a little.","modified":"2026-04-02T08:28:43.382411Z","published":"2025-12-24T12:22:44.765Z","related":["SUSE-SU-2026:0263-1","SUSE-SU-2026:0317-1","SUSE-SU-2026:0411-1","SUSE-SU-2026:0617-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50722.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/5265cc1202a31f7097691c3483a0d60d624424a5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/740717b756c17190dc2d2ad4c6de1e63f214e0c9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b9eb3ab6f30bf32f7326909f17949ccb11bab514"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50722.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-50722"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"0d346d2a6f54f06f36b224fd27cd6eafe8c83be9"},{"fixed":"5265cc1202a31f7097691c3483a0d60d624424a5"},{"fixed":"740717b756c17190dc2d2ad4c6de1e63f214e0c9"},{"fixed":"b9eb3ab6f30bf32f7326909f17949ccb11bab514"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50722.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.14.0"},{"fixed":"5.15.76"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.0.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50722.json"}}],"schema_version":"1.7.5"}