dmaengine: idxd: Prevent use after free on completion memory
Published Aug 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.23%
Description
On driver unload any pending descriptors are flushed at the time the interrupt is freed: idxd_dmaengine_drv_remove() -> drv_disable_wq() -> idxd_wq_free_irq() -> idxd_flush_pending_descs().
If there are any descriptors present that need to be flushed this flow triggers a "not present" page fault as below:
BUG: unable to handle page fault for address: ff391c97c70c9040 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page
The address that triggers the fault is the address of the descriptor that was freed moments earlier via: drv_disable_wq()->idxd_wq_free_resources()
Fix the use after free by freeing the descriptors after any possible usage. This is done after idxd_wq_reset() to ensure that the memory remains accessible during possible completion writes by the device.
Affected products
-
- Version 63c14ae6c161StatusaffectedConstraints<1beeec45f9ac
- Version 63c14ae6c161StatusaffectedConstraints<b9e8e3fcfec6
- Version
-
- Version 5.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.19
- Version 6.1.8StatusunaffectedConstraints<=6.1.*
- Version 6.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.19 · < 6.1.8
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not affected because the kernel config param CONFIG_INTEL_IDXD is disabled.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-48867 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2306388 Issue Tracking
- https://git.kernel.org/stable/c/1beeec45f9ac31eba52478379f70a5fa9c2ad005 Patch
- https://git.kernel.org/stable/c/b9e8e3fcfec625fc1c2f68f684448aeeb882625b Patch
- https://lore.kernel.org/linux-cve-announce/2024082103-CVE-2022-48867-a428@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48867
- https://www.cve.org/CVERecord?id=CVE-2022-48867
Change history (0)
No recorded changes yet.