SUNRPC: lock against ->sock changing during sysfs read
Published Jul 16, 2024
7.8
HIGHCVSS 3.1
EPSS 0.29%
Description
->sock can be set to NULL asynchronously unless ->recv_mutex is held. So it is important to hold that mutex. Otherwise a sysfs read can trigger an oops. Commit 17f09d3f619a ("SUNRPC: Check if the xprt is connected before handling sysfs reads") appears to attempt to fix this problem, but it only narrows the race window.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.10.67StatusaffectedConstraints<5.10.271
- Version 5.13.19StatusaffectedConstraints<5.14
- Version
-
- Version 5.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.14
- Version 5.10.271StatusunaffectedConstraints<=5.10.*
- Version 5.15.209StatusunaffectedConstraints<=5.15.*
- Version 5.16.10StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.10.67 · < 5.11
- ≥ 5.13.19 · < 5.16.10
- 5.17
- 5.17
- 5.17
No data.
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-0:5.14.0-70.117.1.el9_0
Fixed · RHSA-2024:6991
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-rt-0:5.14.0-70.117.1.rt21.189.el9_0
Fixed · RHSA-2024:6990
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-0:5.14.0-70.117.1.el9_0 | Fixed | RHSA-2024:6991 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-rt-0:5.14.0-70.117.1.rt21.189.el9_0 | Fixed | RHSA-2024:6990 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-48816 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298155 Issue Tracking
- https://git.kernel.org/stable/c/9482ab4540f5bcc869b44c067ae99b5fca16bd07 Patch
- https://git.kernel.org/stable/c/b49ea673e119f59c71645e2f65b3ccad857c90ee Patch
- https://git.kernel.org/stable/c/cd366b9091a3e6ed8229e4b908e895d20b527dc0
- https://git.kernel.org/stable/c/fdc42287ae3f8a35cc2098307f52d7864b4bc8ed
- https://lore.kernel.org/linux-cve-announce/2024071648-CVE-2022-48816-e2a3@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48816
- https://www.cve.org/CVERecord?id=CVE-2022-48816
Change history (0)
No recorded changes yet.