cbcvebase.
CVE-2022-48813
published 2024-07-16

CVE-2022-48813: In the Linux kernel, the following vulnerability has been resolved: net: dsa: felix: don't use devres for mdiobus As explained in commits: 74b6d7d13307 ("net…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net: dsa: felix: don't use devres for mdiobus As explained in commits: 74b6d7d13307 ("net: dsa: realtek: register the MDIO bus under devres") 5135e96a3dd2 ("net: dsa: don't allocate the slave_mii_bus using devres") mdiobus_free() will panic when called from devm_mdiobus_free() remove on ->shutdown) do not apply. But there is one more which applies here. If the DSA master itself is on a bus that calls ->remove from ->shutdown (like dpaa2-eth, which is on the fsl-mc bus), there is a device link between the switch and the DSA master, and device_links_unbind_consumers() will unbind the felix switch driver on shutdown. So the same treatment must be applied to all DSA switch drivers, which is: either use devres for both the mdiobus allocation and registration, or don't use devres at all. The felix driver has the code structure in place for orderly mdiobus removal, so just replace devm_mdiobus_alloc_size() with the non-devres variant, and add manual free where necessary, to ensure that we don't let devres free a still-registered bus.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.10-1 (bookworm)linux 5.16.10-1 (bookworm)
linuxlinux
linuxlinux>= ac3a68d56651c3dad2c12c7afce065fe15267f44 < 95e5402f9430b3c7d885dd3ec4c8c02c1793692395e5402f9430b3c7d885dd3ec4c8c02c17936923
linuxlinux>= ac3a68d56651c3dad2c12c7afce065fe15267f44 < 8cda7577a0b4018572f31e0caadfabd305ea27868cda7577a0b4018572f31e0caadfabd305ea2786
linuxlinux>= ac3a68d56651c3dad2c12c7afce065fe15267f44 < 9db6f056efd089e80d81c774c01b639adf30c0979db6f056efd089e80d81c774c01b639adf30c097
linuxlinux>= ac3a68d56651c3dad2c12c7afce065fe15267f44 < 209bdb7ec6a28c7cdf580a0a98afbc9fc3b98932209bdb7ec6a28c7cdf580a0a98afbc9fc3b98932
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 5.11 < 5.15.245.15.24
linuxlinux_kernel>= 5.16 < 5.16.105.16.10
linuxlinux_kernel>= 5.9 < 5.10.1015.10.101

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.