hwmon: (coretemp) Check for null before removing sysfs attrs
Published Oct 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
If coretemp_add_core() gets an error then pdata->core_data[indx] is already NULL and has been kfreed. Don't pass that to sysfs_remove_group() as that will crash in sysfs_remove_group().
[Shortened for readability] [91854.020159] sysfs: cannot create duplicate filename '/devices/platform/coretemp.0/hwmon/hwmon2/temp20_label' <cpu offline> [91855.126115] BUG: kernel NULL pointer dereference, address: 0000000000000188 [91855.165103] #PF: supervisor read access in kernel mode [91855.194506] #PF: error_code(0x0000) - not-present page [91855.224445] PGD 0 P4D 0 [91855.238508] Oops: 0000 [#1] PREEMPT SMP PTI ... [91855.342716] RIP: 0010:sysfs_remove_group+0xc/0x80 ... [91855.796571] Call Trace: [91855.810524] coretemp_cpu_offline+0x12b/0x1dd [coretemp] [91855.841738] ? coretemp_cpu_online+0x180/0x180 [coretemp] [91855.871107] cpuhp_invoke_callback+0x105/0x4b0 [91855.893432] cpuhp_thread_fun+0x8e/0x150 ...
Fix this by checking for NULL first.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.0StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.0
- Version 4.14.301StatusunaffectedConstraints<=4.14.*
- Version 4.19.268StatusunaffectedConstraints<=4.19.*
- Version 4.9.335StatusunaffectedConstraints<=4.9.*
- Version 5.10.158StatusunaffectedConstraints<=5.10.*
- Version 5.15.82StatusunaffectedConstraints<=5.15.*
- Version 5.4.226StatusunaffectedConstraints<=5.4.*
- Version 6.0.12StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 3.0 · < 4.9.335
- ≥ 4.10 · < 4.14.301
- ≥ 4.15 · < 4.19.268
- ≥ 4.20 · < 5.4.226
- ≥ 5.5 · < 5.10.158
- ≥ 5.11 · < 5.15.82
- ≥ 5.16 · < 6.0.12
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is fixed in RHEL-9.2 and above (including RHEL 8.10) ~~~ f1215e1da161 (in rhel-9.2, rhel-9.3, rhel-9.4, rhel-9.5, rhel-9.6) hwmon: (coretemp) Check for null before removing sysfs attrs 5e2e2086e01a (in rhel-8.8, rhel-8.9, rhel-8.10) hwmon: (coretemp) Check for null before removing sysfs attrs ~~~ Please note that while RHEL-9 kernel-rt still appears as affected, it has been fixed in the same RHSA as RHEL-9 kernel. This is because from RHEL-9.3 onwards, the kernel and kernel-rt fixes are bundled together in a single errata.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-49010 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320780 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53894 Advisory
- https://git.kernel.org/stable/c/070d5ea4a0592a37ad96ce7f7b6b024f90bb009f Patch
- https://git.kernel.org/stable/c/280110db1a7d62ad635b103bafc3ae96e8bef75c Patch
- https://git.kernel.org/stable/c/7692700ac818866d138a8de555130a6e70e6ac16 Patch
- https://git.kernel.org/stable/c/89eecabe6a47403237f45aafd7d24f93cb973653 Patch
- https://git.kernel.org/stable/c/a89ff5f5cc64b9fe7a992cf56988fd36f56ca82a Patch
- https://git.kernel.org/stable/c/ae6c8b6e5d5628df1c475c0a8fca1465e205c95b Patch
- https://git.kernel.org/stable/c/f06e0cd01eab954bd5f2190c9faa79bb5357e05b Patch
- https://git.kernel.org/stable/c/fb503d077ff7b43913503eaf72995d1239028b99 Patch
- https://lore.kernel.org/linux-cve-announce/2024102152-CVE-2022-49010-f8e1@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49010
- https://www.cve.org/CVERecord?id=CVE-2022-49010
Change history (0)
No recorded changes yet.