hwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails
Published Oct 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Smatch report warning as follows:
drivers/hwmon/ibmpex.c:509 ibmpex_register_bmc() warn: '&data->list' not removed from list
If ibmpex_find_sensors() fails in ibmpex_register_bmc(), data will be freed, but data->list will not be removed from driver_data.bmc_data, then list traversal may cause UAF.
Fix by removeing it from driver_data.bmc_data before free().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.24StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.24
- Version 4.14.301StatusunaffectedConstraints<=4.14.*
- Version 4.19.268StatusunaffectedConstraints<=4.19.*
- Version 4.9.335StatusunaffectedConstraints<=4.9.*
- Version 5.10.158StatusunaffectedConstraints<=5.10.*
- Version 5.15.82StatusunaffectedConstraints<=5.15.*
- Version 5.4.226StatusunaffectedConstraints<=5.4.*
- Version 6.0.12StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 2.6.24 · < 4.9.335
- ≥ 4.10 · < 4.14.301
- ≥ 4.15 · < 4.19.268
- ≥ 4.20 · < 5.4.226
- ≥ 5.5 · < 5.10.158
- ≥ 5.11 · < 5.15.82
- ≥ 5.16 · < 6.0.12
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.12.1.el9_6
Fixed · RHSA-2025:6966
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.12.1.el9_6
Fixed · RHSA-2025:6966
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel-rt
Will not fix
Red Hat Enterprise Linux 9
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.12.1.el9_6 | Fixed | RHSA-2025:6966 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.12.1.el9_6 | Fixed | RHSA-2025:6966 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is considered to be a moderate impact flaw, as the exploitation for this will need an ADMIN (or ROOT) privilege (PR:H).
Red Hat mitigation
To mitigate this issue, prevent the `ibmpex` kernel module from loading by creating a blacklist file. This action may impact systems that rely on IBM pSeries hardware monitoring. Create a file named `/etc/modprobe.d/blacklist-ibmpex.conf` with the following content: ``` blacklist ibmpex install ibmpex /bin/true ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. For example, on Red Hat Enterprise Linux: ```bash draco-update initramfs reboot ``` Note that a system reboot is required for the mitigation to be fully applied.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-49029 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320693 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53913 Advisory
- https://git.kernel.org/stable/c/24b9633f7db7f4809be7053df1d2e117e7c2de10 Patch
- https://git.kernel.org/stable/c/45f6e81863747c0d7bc6a95ec51129900e71467a Patch
- https://git.kernel.org/stable/c/798198273bf86673b970b51acdb35e57f42b3fcb Patch
- https://git.kernel.org/stable/c/7b2b67fe1339389e0bf3c37c7a677a004ac0e4e3 Patch
- https://git.kernel.org/stable/c/90907cd4d11351ff76c9a447bcb5db0e264c47cd Patch
- https://git.kernel.org/stable/c/e2a87785aab0dac190ac89be6a9ba955e2c634f2 Patch
- https://git.kernel.org/stable/c/e65cfd1f9cd27d9c27ee5cb88128a9f79f25d863 Patch
- https://git.kernel.org/stable/c/f2a13196ad41c6c2ab058279dffe6c97292e753a Patch
- https://lore.kernel.org/linux-cve-announce/2024102155-CVE-2022-49029-0ffd@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49029
- https://www.cve.org/CVERecord?id=CVE-2022-49029
Change history (0)
No recorded changes yet.