afs: Fix dynamic root getattr
Published Feb 26, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.30%
Description
The recent patch to make afs_getattr consult the server didn't account for the pseudo-inodes employed by the dynamic root-type afs superblock not having a volume or a server to access, and thus an oops occurs if such a directory is stat'd.
Fix this by checking to see if the vnode->volume pointer actually points anywhere before following it in afs_getattr().
This can be tested by stat'ing a directory in /afs. It may be sufficient just to do "ls /afs" and the oops looks something like:
BUG: kernel NULL pointer dereference, address: 0000000000000020 ... RIP: 0010:afs_getattr+0x8b/0x14b ... Call Trace: <TASK> vfs_statx+0x79/0xf5 vfs_fstatat+0x49/0x62
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.19.245StatusaffectedConstraints<4.19.250
- Version 5.10.118StatusaffectedConstraints<5.10.127
- Version 5.15.42StatusaffectedConstraints<5.15.51
- Version 5.17.10StatusaffectedConstraints<5.18
- Version 5.4.196StatusaffectedConstraints<5.4.202
- Version
-
- Version 5.18StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.18
- Version 4.19.250StatusunaffectedConstraints<=4.19.*
- Version 5.10.127StatusunaffectedConstraints<=5.10.*
- Version 5.15.51StatusunaffectedConstraints<=5.15.*
- Version 5.18.8StatusunaffectedConstraints<=5.18.*
- Version 5.19StatusunaffectedConstraints<=*
- Version 5.4.202StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.19.245 · < 4.19.250
- ≥ 5.4.196 · < 5.4.202
- ≥ 5.10.118 · < 5.10.127
- ≥ 5.15.42 · < 5.15.51
- ≥ 5.17.10 · < 5.18
- ≥ 5.18.1 · < 5.18.8
- 5.18
- 5.19
- 5.19
- 5.19
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-49688 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2347700 Issue Tracking
- https://git.kernel.org/stable/c/2b2bba96526f25f2eba74ecadb031de2e05a83ce Patch
- https://git.kernel.org/stable/c/65c24caf1b9f5b08397c6e805ec24ebc390c6e4d Patch
- https://git.kernel.org/stable/c/7844ceada44eca740d31beb3d97b8511b1ca0a9b Patch
- https://git.kernel.org/stable/c/7b564e3254b7db5fbfbf11a824627a6c31b932b4 Patch
- https://git.kernel.org/stable/c/cb78d1b5efffe4cf97e16766329dd7358aed3deb Patch
- https://git.kernel.org/stable/c/e3a232e5767051483ffad4cef7d0a89d292a192b Patch
- https://lore.kernel.org/linux-cve-announce/2025022627-CVE-2022-49688-5c71@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49688
- https://www.cve.org/CVERecord?id=CVE-2022-49688
Change history (0)
No recorded changes yet.