net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
Published Aug 22, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
During driver initialization, the pointer of card info, i.e. the variable 'ci' is required. However, the definition of 'com20020pci_id_table' reveals that this field is empty for some devices, which will cause null pointer dereference when initializing these devices.
The following log reveals it:
[ 3.973806] KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f] [ 3.973819] RIP: 0010:com20020pci_probe+0x18d/0x13e0 [com20020_pci] [ 3.975181] Call Trace: [ 3.976208] local_pci_probe+0x13f/0x210 [ 3.977248] pci_device_probe+0x34c/0x6d0 [ 3.977255] ? pci_uevent+0x470/0x470 [ 3.978265] really_probe+0x24c/0x8d0 [ 3.978273] __driver_probe_device+0x1b3/0x280 [ 3.979288] driver_probe_device+0x50/0x370
Fix this by checking whether the 'ci' is a null pointer first.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.18StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.18
- Version 4.14.270StatusunaffectedConstraints<=4.14.*
- Version 4.19.233StatusunaffectedConstraints<=4.19.*
- Version 4.9.305StatusunaffectedConstraints<=4.9.*
- Version 5.10.104StatusunaffectedConstraints<=5.10.*
- Version 5.15.27StatusunaffectedConstraints<=5.15.*
- Version 5.16.13StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version 5.4.183StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 3.18 · < 4.9.305
- ≥ 4.10 · < 4.14.270
- ≥ 4.15 · < 4.19.233
- ≥ 4.20 · < 5.4.183
- ≥ 5.5 · < 5.10.104
- ≥ 5.11 · < 5.15.27
- ≥ 5.16 · < 5.16.13
- 5.17
- 5.17
- 5.17
- 5.17
- 5.17
- 5.17
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not impacted by this CVE, as the vulnerability in question does not affect the specific versions or configurations of the Linux kernel used in its distributions. This ensures that users of Red Hat Enterprise Linux are not exposed to the potential risks associated with this issue, and no further action or mitigation is necessary for systems running this operating system.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-48908 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2307161 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53787 Advisory
- https://git.kernel.org/stable/c/5f394102ee27dbf051a4e283390cd8d1759dacea Patch
- https://git.kernel.org/stable/c/8e3bc7c5bbf87e86e9cd652ca2a9166942d86206 Patch
- https://git.kernel.org/stable/c/b1ee6b9340a38bdb9e5c90f0eac5b22b122c3049 Patch
- https://git.kernel.org/stable/c/b838add93e1dd98210482dc433768daaf752bdef Patch
- https://git.kernel.org/stable/c/bd6f1fd5d33dfe5d1b4f2502d3694a7cc13f166d Patch
- https://git.kernel.org/stable/c/ca0bdff4249a644f2ca7a49d410d95b8dacf1f72 Patch
- https://git.kernel.org/stable/c/e50c589678e50f8d574612e473ca60ef45190896 Patch
- https://git.kernel.org/stable/c/ea372aab54903310756217d81610901a8e66cb7d Patch
- https://lore.kernel.org/linux-cve-announce/2024082213-CVE-2022-48908-27ec@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48908
- https://www.cve.org/CVERecord?id=CVE-2022-48908
Change history (0)
No recorded changes yet.