net: mana: Fix race on per-CQ variable napi work_done
Published Oct 21, 2024
9.8
CRITICALCVSS 3.1
EPSS 0.59%
Description
After calling napi_complete_done(), the NAPIF_STATE_SCHED bit may be cleared, and another CPU can start napi thread and access per-CQ variable, cq->work_done. If the other thread (for example, from busy_poll) sets it to a value >= budget, this thread will continue to run when it should stop, and cause memory corruption and panic.
To fix this issue, save the per-CQ work_done variable in a local variable before napi_complete_done(), so it won't be corrupted by a possible concurrent thread after napi_complete_done().
Also, add a flag bit to advertise to the NIC firmware: the NAPI work_done variable race is fixed, so the driver is able to reliably support features like busy_poll.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.15
- Version 5.15.83StatusunaffectedConstraints<=5.15.*
- Version 6.0.13StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.15 · < 5.15.83
- ≥ 5.16 · < 6.0.13
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The fail could happen for the specific cases (race condition) during this network driver usage. No known attack vectors (apart from possibility of deny of service). The driver enabled only in latest versions of Red Hat Enterprise Linux (8.9 or 9.5).
Red Hat mitigation
To mitigate this issue, prevent module mana from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-48985 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320691 Issue Tracking
- https://git.kernel.org/stable/c/18010ff776fa42340efc428b3ea6d19b3e7c7b21 Patch
- https://git.kernel.org/stable/c/6740d8572ccd1bca50d8a1ca2bedc333f50ed5f3 Patch
- https://git.kernel.org/stable/c/fe50a9bbeb1f042e756c5cfa7708112c944368de Patch
- https://lore.kernel.org/linux-cve-announce/2024102147-CVE-2022-48985-40b5@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48985
- https://www.cve.org/CVERecord?id=CVE-2022-48985
Change history (0)
No recorded changes yet.