bnxt: prevent skb UAF after handing over to PTP worker
Published Apr 28, 2024
7.8
HIGHCVSS 3.1
EPSS 0.23%
Description
When reading the timestamp is required bnxt_tx_int() hands over the ownership of the completed skb to the PTP worker. The skb should not be used afterwards, as the worker may run before the rest of our code and free the skb, leading to a use-after-free.
Since dev_kfree_skb_any() accepts NULL make the loss of ownership more obvious and set skb to NULL.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.14
- Version 5.15.71StatusunaffectedConstraints<=5.15.*
- Version 5.19.12StatusunaffectedConstraints<=5.19.*
- Version 6.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.14 · < 5.15.71
- ≥ 5.16 · < 5.19.12
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
No data.
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.118.1.el8_6
Fixed · RHSA-2024:5281
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.77.1.el9_2
Fixed · RHSA-2024:5066
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.77.1.rt14.362.el9_2
Fixed · RHSA-2024:5067
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.118.1.el8_6 | Fixed | RHSA-2024:5281 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.77.1.el9_2 | Fixed | RHSA-2024:5066 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.77.1.rt14.362.el9_2 | Fixed | RHSA-2024:5067 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-48637 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2277831 Issue Tracking
- https://git.kernel.org/stable/c/08483e4c0c83b221b8891434a04cec405dee94a6 Patch
- https://git.kernel.org/stable/c/32afa1f23e42cc635ccf4c39f24514d03d1e8338 Patch
- https://git.kernel.org/stable/c/c31f26c8f69f776759cbbdfb38e40ea91aa0dd65 Patch
- https://lore.kernel.org/linux-cve-announce/2024042855-CVE-2022-48637-d149@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48637
- https://www.cve.org/CVERecord?id=CVE-2022-48637
Change history (0)
No recorded changes yet.