cbcvebase.
CVE-2022-48812
published 2024-07-16

CVE-2022-48812: In the Linux kernel, the following vulnerability has been resolved: net: dsa: lantiq_gswip: don't use devres for mdiobus As explained in commits: 74b6d7d13307…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.8th percentile
In the Linux kernel, the following vulnerability has been resolved: net: dsa: lantiq_gswip: don't use devres for mdiobus As explained in commits: 74b6d7d13307 ("net: dsa: realtek: register the MDIO bus under devres") 5135e96a3dd2 ("net: dsa: don't allocate the slave_mii_bus using devres") mdiobus_free() will panic when called from devm_mdiobus_free() remove on ->shutdown) do not apply. But there is one more which applies here. If the DSA master itself is on a bus that calls ->remove from ->shutdown (like dpaa2-eth, which is on the fsl-mc bus), there is a device link between the switch and the DSA master, and device_links_unbind_consumers() will unbind the GSWIP switch driver on shutdown. So the same treatment must be applied to all DSA switch drivers, which is: either use devres for both the mdiobus allocation and registration, or don't use devres at all. The gswip driver has the code structure in place for orderly mdiobus removal, so just replace devm_mdiobus_alloc() with the non-devres variant, and add manual free where necessary, to ensure that we don't let devres free a still-registered bus.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.10-1 (bookworm)linux 5.16.10-1 (bookworm)
linuxlinux
linuxlinux>= ac3a68d56651c3dad2c12c7afce065fe15267f44 < e177d2e85ebcd3008c4b2abc293f4118e04eedefe177d2e85ebcd3008c4b2abc293f4118e04eedef
linuxlinux>= ac3a68d56651c3dad2c12c7afce065fe15267f44 < b5652bc50dde7b84e93dfb25479b64b817e377c1b5652bc50dde7b84e93dfb25479b64b817e377c1
linuxlinux>= ac3a68d56651c3dad2c12c7afce065fe15267f44 < 2443ba2fe396bdde187a2fdfa6a57375643ae93c2443ba2fe396bdde187a2fdfa6a57375643ae93c
linuxlinux>= ac3a68d56651c3dad2c12c7afce065fe15267f44 < 0d120dfb5d67edc5bcd1804e167dba2b30809afd0d120dfb5d67edc5bcd1804e167dba2b30809afd
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 5.11 < 5.15.245.15.24
linuxlinux_kernel>= 5.16 < 5.16.105.16.10
linuxlinux_kernel>= 5.9 < 5.10.1015.10.101

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.