sysctl: Fix data races in proc_douintvec_minmax().
Published Feb 26, 2025
4.7
MEDIUMCVSS 3.1
EPSS 0.18%
Description
A sysctl variable is accessed concurrently, and there is always a chance of data-race. So, all readers and writers need some basic protection to avoid load/store-tearing.
This patch changes proc_douintvec_minmax() to use READ_ONCE() and WRITE_ONCE() internally to fix data-races on the sysctl side. For now, proc_douintvec_minmax() itself is tolerant to a data-race, but we still need to add annotations on the other subsystem's side.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.13StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.13
- Version 5.10.132StatusunaffectedConstraints<=5.10.*
- Version 5.15.56StatusunaffectedConstraints<=5.15.*
- Version 5.18.13StatusunaffectedConstraints<=5.18.*
- Version 5.19StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 4.13 · < 5.10.132
- ≥ 5.11 · < 5.15.56
- ≥ 5.16 · < 5.18.13
- 5.19
- 5.19
- 5.19
- 5.19
- 5.19
- 5.19
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The bug can lead to incorrect numerical value being read with sysctl for some specific cases if race condition happened (when both modifying this value and reading). The security impact is limited, because no known vectors of attack and no actual kernel panic or other fail. The bug actual only for Red Hat Enterprise Linux 8 and already fixed in Red Hat Enterprise Linux 9 and later versions. The bug could happen only for the case of reading (with in parallel modifying) of specific type of values "a vector of unsigned ints with min/max values" and the max impact could be incorrect values being read.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-49640 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2348184 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-54592 Advisory
- https://git.kernel.org/stable/c/2d3b559df3ed39258737789aae2ae7973d205bc1 Patch
- https://git.kernel.org/stable/c/40e0477a7371d101c55b69d9c32a7a1ed82ab5ea Patch
- https://git.kernel.org/stable/c/b60eddf98b9716651069dfda296c91311a7a6293 Patch
- https://git.kernel.org/stable/c/e3a2144b3b6bf9ecafd91087c8b8b48171ec19df Patch
- https://lore.kernel.org/linux-cve-announce/2025022618-CVE-2022-49640-96ed@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49640
- https://www.cve.org/CVERecord?id=CVE-2022-49640
Change history (0)
No recorded changes yet.