cbcvebase.
CVE-2022-48850
published 2024-07-16

CVE-2022-48850: In the Linux kernel, the following vulnerability has been resolved: net-sysfs: add check for netdevice being present to speed_show When bringing down the…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net-sysfs: add check for netdevice being present to speed_show When bringing down the netdevice or system shutdown, a panic can be triggered while accessing the sysfs path because the device is already removed. [ 755.549084] mlx5_core 0000:12:00.1: Shutdown was called [ 756.404455] mlx5_core 0000:12:00.0: Shutdown was called ... [ 757.937260] BUG: unable to handle kernel NULL pointer dereference at (null) [ 758.031397] IP: [] dma_pool_alloc+0x1ab/0x280 crash> bt ... PID: 12649 TASK: ffff8924108f2100 CPU: 1 COMMAND: "amsd" ... #9 [ffff89240e1a38b0] page_fault at ffffffff8f38c778 [exception RIP: dma_pool_alloc+0x1ab] RIP: ffffffff8ee11acb RSP: ffff89240e1a3968 RFLAGS: 00010046 RAX: 0000000000000246 RBX: ffff89243d874100 RCX: 0000000000001000 RDX: 0000000000000000 RSI: 0000000000000246 RDI: ffff89243d874090 RBP: ffff89240e1a39c0 R8: 000000000001f080 R9: ffff8905ffc03c00 R10: ffffffffc04680d4 R11: ffffffff8edde9fd R12: 00000000000080d0 R13: ffff89243d874090 R14: ffff89243d874080 R15: 0000000000000000 ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018 #10 [ffff89240e1a39c8] mlx5_alloc_cmd_msg at ffffffffc04680f3 [mlx5_core] #11 [ffff89240e1a3a18] cmd_exec at ffffffffc046ad62 [mlx5_core] #12 [ffff89240e1a3ab8] mlx5_cmd_exec at ffffffffc046b4fb [mlx5_core] #13 [ffff89240e1a3ae8] mlx5_core_access_reg at ffffffffc0475434 [mlx5_core] #14 [ffff89240e1a3b40] mlx5e_get_fec_caps at ffffffffc04a7348 [mlx5_core] #15 [ffff89240e1a3bb0] get_fec_supported_advertised at ffffffffc04992bf [mlx5_core] #16 [ffff89240e1a3c08] mlx5e_get_link_ksettings at ffffffffc049ab36 [mlx5_core] #17 [ffff89240e1a3ce8] __ethtool_get_link_ksettings at ffffffff8f25db46 #18 [ffff89240e1a3d48] speed_show at ffffffff8f277208 #19 [ffff89240e1a3dd8] dev_attr_show at ffffffff8f0b70e3 #20 [ffff89240e1a3df8] sysfs_kf_seq_show at ffffffff8eedbedf #21 [ffff89240e1a3e18] kernfs_seq_show at ffffffff8eeda596 #22 [ffff89240e1a3e28] seq_read at ffffffff8ee7

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.18-1 (bookworm)linux 5.16.18-1 (bookworm)
linuxlinux
linuxlinux>= d519e17e2d01a0ee9abe083019532061b4438065 < a7b9ab04c5932dee7ec95e0abc58b0df350c0dd2a7b9ab04c5932dee7ec95e0abc58b0df350c0dd2
linuxlinux>= d519e17e2d01a0ee9abe083019532061b4438065 < 081369ad088a76429984483b8a5f7e967a125aad081369ad088a76429984483b8a5f7e967a125aad
linuxlinux>= d519e17e2d01a0ee9abe083019532061b4438065 < 75fc8363227a999e8f3d17e2eb28dce5600dcd3f75fc8363227a999e8f3d17e2eb28dce5600dcd3f
linuxlinux>= d519e17e2d01a0ee9abe083019532061b4438065 < 8879b5313e9fa5e0c6d6812a0d25d83aed0110e28879b5313e9fa5e0c6d6812a0d25d83aed0110e2
linuxlinux>= d519e17e2d01a0ee9abe083019532061b4438065 < d15c9f6e3335002fea1c33bc8f71a705fa96976cd15c9f6e3335002fea1c33bc8f71a705fa96976c
linuxlinux>= d519e17e2d01a0ee9abe083019532061b4438065 < 8d5e69d8fbf3a35ab4fbe56b8f092802b43f3ef68d5e69d8fbf3a35ab4fbe56b8f092802b43f3ef6
linuxlinux>= d519e17e2d01a0ee9abe083019532061b4438065 < 3a79f380b3e10edf6caa9aac90163a5d7a2822043a79f380b3e10edf6caa9aac90163a5d7a282204
linuxlinux>= d519e17e2d01a0ee9abe083019532061b4438065 < 4224cfd7fb6523f7a9d1c8bb91bb5df1e38eb6244224cfd7fb6523f7a9d1c8bb91bb5df1e38eb624
linuxlinux_kernel< 4.9.3074.9.307
linuxlinux_kernel>= 0 < 5.10.106-15.10.106-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 4.4.0-259.2934.4.0-259.293
linuxlinux_kernel>= 4.10 < 4.14.2724.14.272
linuxlinux_kernel>= 4.15 < 4.19.2354.19.235
linuxlinux_kernel>= 4.20 < 5.4.1855.4.185
linuxlinux_kernel>= 5.11 < 5.15.295.15.29
linuxlinux_kernel>= 5.16 < 5.16.155.16.15
linuxlinux_kernel>= 5.5 < 5.10.1065.10.106

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.