CVE-2022-48704
published 2024-05-03CVE-2022-48704: In the Linux kernel, the following vulnerability has been resolved: drm/radeon: add a force flush to delay work when radeon Although radeon card fence and wait…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: add a force flush to delay work when radeon
Although radeon card fence and wait for gpu to finish processing current batch rings,
there is still a corner case that radeon lockup work queue may not be fully flushed,
and meanwhile the radeon_suspend_kms() function has called pci_set_power_state() to
put device in D3hot state.
Per PCI spec rev 4.0 on 5.3.1.4.1 D3hot State.
> Configuration and Message requests are the only TLPs accepted by a Function in
> the D3hot state. All other received Requests must be handled as Unsupported Requests,
> and all received Completions may optionally be handled as Unexpected Completions.
This issue will happen in following logs:
Unable to handle kernel paging request at virtual address 00008800e0008010
CPU 0 kworker/0:3(131): Oops 0
pc = [] ra = [] ps = 0000 Tainted: G W
pc is at si_gpu_check_soft_reset+0x3c/0x240
ra is at si_dma_is_lockup+0x34/0xd0
v0 = 0000000000000000 t0 = fff08800e0008010 t1 = 0000000000010000
t2 = 0000000000008010 t3 = fff00007e3c00000 t4 = fff00007e3c00258
t5 = 000000000000ffff t6 = 0000000000000001 t7 = fff00007ef078000
s0 = fff00007e3c016e8 s1 = fff00007e3c00000 s2 = fff00007e3c00018
s3 = fff00007e3c00000 s4 = fff00007fff59d80 s5 = 0000000000000000
s6 = fff00007ef07bd98
a0 = fff00007e3c00000 a1 = fff00007e3c016e8 a2 = 0000000000000008
a3 = 0000000000000001 a4 = 8f5c28f5c28f5c29 a5 = ffffffff810f4338
t8 = 0000000000000275 t9 = ffffffff809b66f8 t10 = ff6769c5d964b800
t11= 000000000000b886 pv = ffffffff811bea20 at = 0000000000000000
gp = ffffffff81d89690 sp = 00000000aa814126
Disabling lock debugging due to kernel taint
Trace:
[] si_dma_is_lockup+0x34/0xd0
[] radeon_fence_check_lockup+0xd0/0x290
[] process_one_work+0x280/0x550
[] worker_thread+0x70/0x7c0
[] worker_thread+0x130/0x7c0
[] kthread+0x200/0x210
[] worker_thread+0x0/0x7c0
[] kthread+0x14c/0x210
[] ret_from_kernel_thread+0x18/0x20
[] kthread+0x0/0x210
Code: ad3e0008 43f0074a
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.19.11-1 (bookworm) | linux 5.19.11-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 0bfa4b41268ad5fd741f16f484e4fee190822ec6 < b878da58df2c40b08914d3960e2224040fd1fbfe | b878da58df2c40b08914d3960e2224040fd1fbfe |
| linux | linux | >= 0bfa4b41268ad5fd741f16f484e4fee190822ec6 < 4e25e8f27fdbdc6fd55cc572a9939bf24500b9e8 | 4e25e8f27fdbdc6fd55cc572a9939bf24500b9e8 |
| linux | linux | >= 0bfa4b41268ad5fd741f16f484e4fee190822ec6 < c0a45f41fde4a0f2c900f719817493ee5c4a5aa3 | c0a45f41fde4a0f2c900f719817493ee5c4a5aa3 |
| linux | linux | >= 0bfa4b41268ad5fd741f16f484e4fee190822ec6 < c72d97146fc5a4dff381b1737f6167e89860430d | c72d97146fc5a4dff381b1737f6167e89860430d |
| linux | linux | >= 0bfa4b41268ad5fd741f16f484e4fee190822ec6 < 826b46fd5974113515abe9e4fc8178009a8ce18c | 826b46fd5974113515abe9e4fc8178009a8ce18c |
| linux | linux | >= 0bfa4b41268ad5fd741f16f484e4fee190822ec6 < 5a7a5b2edac4b05abd744eeaebda46d9dacd952d | 5a7a5b2edac4b05abd744eeaebda46d9dacd952d |
| linux | linux | >= 0bfa4b41268ad5fd741f16f484e4fee190822ec6 < 16cb367daa446923d82e332537f446a4cc784b40 | 16cb367daa446923d82e332537f446a4cc784b40 |
| linux | linux | >= 0bfa4b41268ad5fd741f16f484e4fee190822ec6 < f461950fdc374a3ada5a63c669d997de4600dffe | f461950fdc374a3ada5a63c669d997de4600dffe |
| linux | linux_kernel | < 4.9.328 | 4.9.328 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.148-1 | 5.10.148-1 |
| linux | linux_kernel | >= 0 < 5.19.11-1 | 5.19.11-1 |
| linux | linux_kernel | >= 0 < 5.19.11-1 | 5.19.11-1 |
| linux | linux_kernel | >= 0 < 5.19.11-1 | 5.19.11-1 |
| linux | linux_kernel | >= 4.10 < 4.14.293 | 4.14.293 |
| linux | linux_kernel | >= 4.15 < 4.19.258 | 4.19.258 |
| linux | linux_kernel | >= 4.20 < 5.4.213 | 5.4.213 |
| linux | linux_kernel | >= 5.11 < 5.15.68 | 5.15.68 |
| linux | linux_kernel | >= 5.16 < 5.19.9 | 5.19.9 |
| linux | linux_kernel | >= 5.5 < 5.10.143 | 5.10.143 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: drm/radeon: add a force flush to delay work when radeon
vendor_redhat·2024-05-03·CVSS 5.5
CVE-2022-48704 [MEDIUM] kernel: drm/radeon: add a force flush to delay work when radeon
kernel: drm/radeon: add a force flush to delay work when radeon
In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: add a force flush to delay work when radeon
Although radeon card fence and wait for gpu to finish processing current batch rings,
there is still a corner case that radeon lockup work queue may not be fully flushed,
and meanwhile the radeon_suspend_kms() function has called pci_set_power_state() to
put device in D3hot state.
Per PCI spec rev 4.0 on 5.3.1.4.1 D3hot State.
> Configuration and Message requests are the only TLPs accepted by a Function in
> the D3hot state. All other received Requests must be handled as Unsupported Requests,
> and all received Completions may optionally be handled as Unexpected Completions.
This issue will happen in fol
Debian
CVE-2022-48704: linux - In the Linux kernel, the following vulnerability has been resolved: drm/radeon:...
vendor_debian·2022·CVSS 5.5
CVE-2022-48704 [MEDIUM] CVE-2022-48704: linux - In the Linux kernel, the following vulnerability has been resolved: drm/radeon:...
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: add a force flush to delay work when radeon Although radeon card fence and wait for gpu to finish processing current batch rings, there is still a corner case that radeon lockup work queue may not be fully flushed, and meanwhile the radeon_suspend_kms() function has called pci_set_power_state() to put device in D3hot state. Per PCI spec rev 4.0 on 5.3.1.4.1 D3hot State. > Configuration and Message requests are the only TLPs accepted by a Function in > the D3hot state. All other received Requests must be handled as Unsupported Requests, > and all received Completions may optionally be handled as Unexpected Completions. This issue will happen in following logs: Unable to handle kernel paging request at virtual ad
GHSA
GHSA-pvc2-5xx8-q6h9: In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: add a force flush to delay work when radeon
Although radeon card fen
ghsa_unreviewed·2024-05-03
CVE-2022-48704 [MEDIUM] GHSA-pvc2-5xx8-q6h9: In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: add a force flush to delay work when radeon
Although radeon card fen
In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: add a force flush to delay work when radeon
Although radeon card fence and wait for gpu to finish processing current batch rings,
there is still a corner case that radeon lockup work queue may not be fully flushed,
and meanwhile the radeon_suspend_kms() function has called pci_set_power_state() to
put device in D3hot state.
Per PCI spec rev 4.0 on 5.3.1.4.1 D3hot State.
> Configuration and Message requests are the only TLPs accepted by a Function in
> the D3hot state. All other received Requests must be handled as Unsupported Requests,
> and all received Completions may optionally be handled as Unexpected Completions.
This issue will happen in following logs:
Unable to handle kernel paging request at virtual
OSV
CVE-2022-48704: In the Linux kernel, the following vulnerability has been resolved: drm/radeon: add a force flush to delay work when radeon Although radeon card fence
osv·2024-05-03·CVSS 5.5
CVE-2022-48704 [MEDIUM] CVE-2022-48704: In the Linux kernel, the following vulnerability has been resolved: drm/radeon: add a force flush to delay work when radeon Although radeon card fence
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: add a force flush to delay work when radeon Although radeon card fence and wait for gpu to finish processing current batch rings, there is still a corner case that radeon lockup work queue may not be fully flushed, and meanwhile the radeon_suspend_kms() function has called pci_set_power_state() to put device in D3hot state. Per PCI spec rev 4.0 on 5.3.1.4.1 D3hot State. > Configuration and Message requests are the only TLPs accepted by a Function in > the D3hot state. All other received Requests must be handled as Unsupported Requests, > and all received Completions may optionally be handled as Unexpected Completions. This issue will happen in following logs: Unable to handle kernel paging request at virtual ad
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/16cb367daa446923d82e332537f446a4cc784b40https://git.kernel.org/stable/c/4e25e8f27fdbdc6fd55cc572a9939bf24500b9e8https://git.kernel.org/stable/c/5a7a5b2edac4b05abd744eeaebda46d9dacd952dhttps://git.kernel.org/stable/c/826b46fd5974113515abe9e4fc8178009a8ce18chttps://git.kernel.org/stable/c/b878da58df2c40b08914d3960e2224040fd1fbfehttps://git.kernel.org/stable/c/c0a45f41fde4a0f2c900f719817493ee5c4a5aa3https://git.kernel.org/stable/c/c72d97146fc5a4dff381b1737f6167e89860430dhttps://git.kernel.org/stable/c/f461950fdc374a3ada5a63c669d997de4600dffehttps://git.kernel.org/stable/c/16cb367daa446923d82e332537f446a4cc784b40https://git.kernel.org/stable/c/4e25e8f27fdbdc6fd55cc572a9939bf24500b9e8https://git.kernel.org/stable/c/5a7a5b2edac4b05abd744eeaebda46d9dacd952dhttps://git.kernel.org/stable/c/826b46fd5974113515abe9e4fc8178009a8ce18chttps://git.kernel.org/stable/c/b878da58df2c40b08914d3960e2224040fd1fbfehttps://git.kernel.org/stable/c/c0a45f41fde4a0f2c900f719817493ee5c4a5aa3https://git.kernel.org/stable/c/c72d97146fc5a4dff381b1737f6167e89860430dhttps://git.kernel.org/stable/c/f461950fdc374a3ada5a63c669d997de4600dffe
2024-05-03
Published