ThreatCluster

Multiple CVEs Address NULL Dereference Vulnerabilities in SPRD Components

First seen 18 Feb 2026, 12:23 UTC Api.Msrc.Microsoft 46

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in SPRD components, specifically CVE-2022-49125 and CVE-2024-42277. CVE-2022-49125, published on February 26, 2025, addresses a potential NULL dereference in the drm/sprd module, while CVE-2024-42277, published on August 17, 2024, focuses on avoiding NULL dereference in the sprd_iommu_hw_en function. Both vulnerabilities could impact systems utilizing these components.

Timeline

2024-08-17
CVE-2024-42277 published
2025-02-26
CVE-2022-49125 published
2026-02-18
Information published about both CVEs