ring-buffer: Check for NULL cpu_buffer in ring_buffer_wake_waiters()
Published May 1, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.20%
Description
On some machines the number of listed CPUs may be bigger than the actual CPUs that exist. The tracing subsystem allocates a per_cpu directory with access to the per CPU ring buffer via a cpuX file. But to save space, the ring buffer will only allocate buffers for online CPUs, even though the CPU array will be as big as the nr_cpu_ids.
With the addition of waking waiters on the ring buffer when closing the file, the ring_buffer_wake_waiters() now needs to make sure that the buffer is allocated (with the irq_work allocated with it) before trying to wake waiters, as it will cause a NULL pointer dereference.
While debugging this, I added a NULL check for the buffer itself (which is OK to do), and also NULL pointer checks against buffer->buffers (which is not fine, and will WARN) as well as making sure the CPU number passed in is within the nr_cpu_ids (which is also not fine if it isn't).
Bugzilla: https://bugzilla.opensuse.org/show_bug.cgi?id=1204705
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- ≥ 5.15.75, < 5.15.78
- ≥ 5.19.17, < 5.20
- ≥ 6.0.3, < 6.0.8
- ≥ 5.15.75 · < 5.15.78
- ≥ 5.19.17 · < 6.0
- ≥ 6.0.3 · < 6.0.8
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-49889 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2363445 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12881 Advisory
- https://git.kernel.org/stable/c/49ca992f6e50d0f46ec9608f44e011cf3121f389 Patch
- https://git.kernel.org/stable/c/7433632c9ff68a991bd0bc38cabf354e9d2de410 Patch
- https://git.kernel.org/stable/c/b5074df412bf3df9d6ce096b6fa03eb1082d05c9 Patch
- https://lore.kernel.org/linux-cve-announce/2025050157-CVE-2022-49889-ff97@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49889
- https://www.cve.org/CVERecord?id=CVE-2022-49889
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data