net: fix a memleak when uncloning an skb dst and its metadata
Published Jul 16, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.28%
Description
When uncloning an skb dst and its associated metadata, a new dst+metadata is allocated and later replaces the old one in the skb. This is helpful to have a non-shared dst+metadata attached to a specific skb.
The issue is the uncloned dst+metadata is initialized with a refcount of 1, which is increased to 2 before attaching it to the skb. When tun_dst_unclone returns, the dst+metadata is only referenced from a single place (the skb) while its refcount is 2. Its refcount will never drop to 0 (when the skb is consumed), leading to a memory leak.
Fix this by removing the call to dst_hold in tun_dst_unclone, as the dst+metadata refcount is already 1.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.3StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.3
- Version 4.14.267StatusunaffectedConstraints<=4.14.*
- Version 4.19.230StatusunaffectedConstraints<=4.19.*
- Version 4.9.302StatusunaffectedConstraints<=4.9.*
- Version 5.10.101StatusunaffectedConstraints<=5.10.*
- Version 5.15.24StatusunaffectedConstraints<=5.15.*
- Version 5.16.10StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version 5.4.180StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.3 · < 4.9.302
- ≥ 4.10 · < 4.14.267
- ≥ 4.15 · < 4.19.230
- ≥ 4.20 · < 5.4.180
- ≥ 5.5 · < 5.10.101
- ≥ 5.11 · < 5.15.24
- ≥ 5.16 · < 5.16.10
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2022-48809 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298145 Issue Tracking
- https://git.kernel.org/stable/c/00e6d6c3bc14dfe32824e2c515f0e0f2d6ecf2f1 Patch
- https://git.kernel.org/stable/c/0be943916d781df2b652793bb2d3ae4f9624c10a Patch
- https://git.kernel.org/stable/c/4ac84498fbe84a00e7aef185e2bb3e40ce71eca4 Patch
- https://git.kernel.org/stable/c/8b1087b998e273f07be13dcb5f3ca4c309c7f108 Patch
- https://git.kernel.org/stable/c/9eeabdf17fa0ab75381045c867c370f4cc75a613 Patch
- https://git.kernel.org/stable/c/a80817adc2a4c1ba26a7aa5f3ed886e4a18dff88 Patch
- https://git.kernel.org/stable/c/c1ff27d100e2670b03cbfddb9117e5f9fc672540 Patch
- https://git.kernel.org/stable/c/fdcb263fa5cda15b8cb24a641fa2718c47605314 Patch
- https://lore.kernel.org/linux-cve-announce/2024071646-CVE-2022-48809-ba13@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48809
- https://www.cve.org/CVERecord?id=CVE-2022-48809
Change history (0)
No recorded changes yet.