CVE-2022-48797
published 2024-07-16CVE-2022-48797: In the Linux kernel, the following vulnerability has been resolved: mm: don't try to NUMA-migrate COW pages that have other uses Oded Gabbay reports that…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
mm: don't try to NUMA-migrate COW pages that have other uses
Oded Gabbay reports that enabling NUMA balancing causes corruption with
his Gaudi accelerator test load:
"All the details are in the bug, but the bottom line is that somehow,
this patch causes corruption when the numa balancing feature is
enabled AND we don't use process affinity AND we use GUP to pin pages
so our accelerator can DMA to/from system memory.
Either disabling numa balancing, using process affinity to bind to
specific numa-node or reverting this patch causes the bug to
disappear"
and Oded bisected the issue to commit 09854ba94c6a ("mm: do_wp_page()
simplification").
Now, the NUMA balancing shouldn't actually be changing the writability
of a page, and as such shouldn't matter for COW. But it appears it
does. Suspicious.
However, regardless of that, the condition for enabling NUMA faults in
change_pte_range() is nonsensical. It uses "page_mapcount(page)" to
decide if a COW page should be NUMA-protected or not, and that makes
absolutely no sense.
The number of mappings a page has is irrelevant: not only does GUP get a
reference to a page as in Oded's case, but the other mappings migth be
paged out and the only reference to them would be in the page count.
Since we should never try to NUMA-balance a page that we can't move
anyway due to other references, just fix the code to use 'page_count()'.
Oded confirms that that fixes his issue.
Now, this does imply that something in NUMA balancing ends up changing
page protections (other than the obvious one of making the page
inaccessible to get the NUMA faulting information). Otherwise the COW
simplification wouldn't matter - since doing the GUP on the page would
make sure it's writable.
The cause of that permission change would be good to figure out too,
since it clearly results in spurious COW events - but fixing the
nonsensical test that just happened to work before is obvio
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.11-1 (bookworm) | linux 5.16.11-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 09854ba94c6aad7886996bfbee2530b3d8a7f4f4 < 254090925e16abd914c87b4ad1b489440d89c4c3 | 254090925e16abd914c87b4ad1b489440d89c4c3 |
| linux | linux | >= 09854ba94c6aad7886996bfbee2530b3d8a7f4f4 < b3dc4b9d3ca68b370c4aeab5355007eedf948849 | b3dc4b9d3ca68b370c4aeab5355007eedf948849 |
| linux | linux | >= 09854ba94c6aad7886996bfbee2530b3d8a7f4f4 < d187eeb02d18446e5e54ed6bcbf8b47e6551daea | d187eeb02d18446e5e54ed6bcbf8b47e6551daea |
| linux | linux | >= 09854ba94c6aad7886996bfbee2530b3d8a7f4f4 < 80d47f5de5e311cbc0d01ebb6ee684e8f4c196c6 | 80d47f5de5e311cbc0d01ebb6ee684e8f4c196c6 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.103-1 | 5.10.103-1 |
| linux | linux_kernel | >= 0 < 5.16.11-1 | 5.16.11-1 |
| linux | linux_kernel | >= 0 < 5.16.11-1 | 5.16.11-1 |
| linux | linux_kernel | >= 0 < 5.16.11-1 | 5.16.11-1 |
| linux | linux_kernel | >= 5.11 < 5.15.25 | 5.15.25 |
| linux | linux_kernel | >= 5.16 < 5.16.11 | 5.16.11 |
| linux | linux_kernel | >= 5.9.1 < 5.10.102 | 5.10.102 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: mm: don't try to NUMA-migrate COW pages that have other uses
vendor_redhat·2024-07-16·CVSS 5.5
CVE-2022-48797 [MEDIUM] CWE-275 kernel: mm: don't try to NUMA-migrate COW pages that have other uses
kernel: mm: don't try to NUMA-migrate COW pages that have other uses
In the Linux kernel, the following vulnerability has been resolved:
mm: don't try to NUMA-migrate COW pages that have other uses
Oded Gabbay reports that enabling NUMA balancing causes corruption with
his Gaudi accelerator test load:
"All the details are in the bug, but the bottom line is that somehow,
this patch causes corruption when the numa balancing feature is
enabled AND we don't use process affinity AND we use GUP to pin pages
so our accelerator can DMA to/from system memory.
Either disabling numa balancing, using process affinity to bind to
specific numa-node or reverting this patch causes the bug to
disappear"
and Oded bisected the issue to commit 09854ba94c6a ("mm: do_wp_page()
simplification").
Now, the NUMA b
Debian
CVE-2022-48797: linux - In the Linux kernel, the following vulnerability has been resolved: mm: don't t...
vendor_debian·2022·CVSS 5.5
CVE-2022-48797 [MEDIUM] CVE-2022-48797: linux - In the Linux kernel, the following vulnerability has been resolved: mm: don't t...
In the Linux kernel, the following vulnerability has been resolved: mm: don't try to NUMA-migrate COW pages that have other uses Oded Gabbay reports that enabling NUMA balancing causes corruption with his Gaudi accelerator test load: "All the details are in the bug, but the bottom line is that somehow, this patch causes corruption when the numa balancing feature is enabled AND we don't use process affinity AND we use GUP to pin pages so our accelerator can DMA to/from system memory. Either disabling numa balancing, using process affinity to bind to specific numa-node or reverting this patch causes the bug to disappear" and Oded bisected the issue to commit 09854ba94c6a ("mm: do_wp_page() simplification"). Now, the NUMA balancing shouldn't actually be changing the writability of a page, and
VulDB
Linux Kernel up to 5.10.101/5.15.24/5.16.10 COW Page do_wp_page permission (WID-SEC-2024-1625)
vuldb·2026-07-11·CVSS 5.5
CVE-2022-48797 [MEDIUM] Linux Kernel up to 5.10.101/5.15.24/5.16.10 COW Page do_wp_page permission (WID-SEC-2024-1625)
A vulnerability labeled as critical has been found in Linux Kernel up to 5.10.101/5.15.24/5.16.10. The affected element is the function do_wp_page of the component COW Page Handler. The manipulation results in permission issues.
This vulnerability is identified as CVE-2022-48797. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
GHSA
GHSA-8ccr-7w7q-vmr3: In the Linux kernel, the following vulnerability has been resolved:
mm: don't try to NUMA-migrate COW pages that have other uses
Oded Gabbay reports
ghsa_unreviewed·2024-07-16
CVE-2022-48797 [MEDIUM] GHSA-8ccr-7w7q-vmr3: In the Linux kernel, the following vulnerability has been resolved:
mm: don't try to NUMA-migrate COW pages that have other uses
Oded Gabbay reports
In the Linux kernel, the following vulnerability has been resolved:
mm: don't try to NUMA-migrate COW pages that have other uses
Oded Gabbay reports that enabling NUMA balancing causes corruption with
his Gaudi accelerator test load:
"All the details are in the bug, but the bottom line is that somehow,
this patch causes corruption when the numa balancing feature is
enabled AND we don't use process affinity AND we use GUP to pin pages
so our accelerator can DMA to/from system memory.
Either disabling numa balancing, using process affinity to bind to
specific numa-node or reverting this patch causes the bug to
disappear"
and Oded bisected the issue to commit 09854ba94c6a ("mm: do_wp_page()
simplification").
Now, the NUMA balancing shouldn't actually be changing the writability
of a pag
OSV
CVE-2022-48797: In the Linux kernel, the following vulnerability has been resolved: mm: don't try to NUMA-migrate COW pages that have other uses Oded Gabbay reports t
osv·2024-07-16·CVSS 5.5
CVE-2022-48797 [MEDIUM] CVE-2022-48797: In the Linux kernel, the following vulnerability has been resolved: mm: don't try to NUMA-migrate COW pages that have other uses Oded Gabbay reports t
In the Linux kernel, the following vulnerability has been resolved: mm: don't try to NUMA-migrate COW pages that have other uses Oded Gabbay reports that enabling NUMA balancing causes corruption with his Gaudi accelerator test load: "All the details are in the bug, but the bottom line is that somehow, this patch causes corruption when the numa balancing feature is enabled AND we don't use process affinity AND we use GUP to pin pages so our accelerator can DMA to/from system memory. Either disabling numa balancing, using process affinity to bind to specific numa-node or reverting this patch causes the bug to disappear" and Oded bisected the issue to commit 09854ba94c6a ("mm: do_wp_page() simplification"). Now, the NUMA balancing shouldn't actually be changing the writability of a page, and
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/254090925e16abd914c87b4ad1b489440d89c4c3https://git.kernel.org/stable/c/80d47f5de5e311cbc0d01ebb6ee684e8f4c196c6https://git.kernel.org/stable/c/b3dc4b9d3ca68b370c4aeab5355007eedf948849https://git.kernel.org/stable/c/d187eeb02d18446e5e54ed6bcbf8b47e6551daeahttps://git.kernel.org/stable/c/254090925e16abd914c87b4ad1b489440d89c4c3https://git.kernel.org/stable/c/80d47f5de5e311cbc0d01ebb6ee684e8f4c196c6https://git.kernel.org/stable/c/b3dc4b9d3ca68b370c4aeab5355007eedf948849https://git.kernel.org/stable/c/d187eeb02d18446e5e54ed6bcbf8b47e6551daea
2024-07-16
Published