bpf, sockmap: Fix double uncharge the mem of sk_msg
Published Feb 26, 2025
7.8
HIGHCVSS 3.1
EPSS 0.28%
Description
If tcp_bpf_sendmsg is running during a tear down operation, psock may be freed.
tcp_bpf_sendmsg() tcp_bpf_send_verdict() sk_msg_return() tcp_bpf_sendmsg_redir() unlikely(!psock)) sk_msg_free()
The mem of msg has been uncharged in tcp_bpf_send_verdict() by sk_msg_return(), and would be uncharged by sk_msg_free() again. When psock is null, we can simply returning an error code, this would then trigger the sk_msg_free_nocharge in the error path of __SK_REDIRECT and would have the side effect of throwing an error up to user space. This would be a slight change in behavior from user side but would look the same as an error if the redirect on the socket threw an error.
This issue can cause the following info: WARNING: CPU: 0 PID: 2136 at net/ipv4/af_inet.c:155 inet_sock_destruct+0x13c/0x260 Call Trace: <TASK> __sk_destruct+0x24/0x1f0 sk_psock_destroy+0x19b/0x1c0 process_one_work+0x1b3/0x3c0 worker_thread+0x30/0x350 ? process_one_work+0x3c0/0x3c0 kthread+0xe6/0x110 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x22/0x30 </TASK>
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 4.20
Unaffected
- ≥ 0, < 4.20
- ≥ 5.10.110, ≤ 5.10.*
- ≥ 5.15.33, ≤ 5.15.*
- ≥ 5.16.19, ≤ 5.16.*
- ≥ 5.17.2, ≤ 5.17.*
- 5.18
- ≥ 5.4.189, ≤ 5.4.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 4.20 · < 5.4.189
- ≥ 5.5 · < 5.10.110
- ≥ 5.11 · < 5.15.33
- ≥ 5.16 · < 5.16.19
- ≥ 5.17 · < 5.17.2
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2022-49205 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2348068 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55021 Advisory
- https://git.kernel.org/stable/c/223f3c51ab163852dd4819d357dcf33039929434 Patch
- https://git.kernel.org/stable/c/2486ab434b2c2a14e9237296db00b1e1b7ae3273 Patch
- https://git.kernel.org/stable/c/94c6ac22abcdede72bfaa0f4c22fb370891f4002 Patch
- https://git.kernel.org/stable/c/ac3ecb7760c750c8e4fc09c719241d8e6e88028c Patch
- https://git.kernel.org/stable/c/cb6f141ae705af0101e819065a79e6d029f6e393 Patch
- https://git.kernel.org/stable/c/cd84ea3920aef936c559b63099ef0013ce6b2325 Patch
- https://lore.kernel.org/linux-cve-announce/2025022618-CVE-2022-49205-5180@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49205
- https://www.cve.org/CVERecord?id=CVE-2022-49205
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data