CVE-2022-48954
published 2024-10-21CVE-2022-48954: In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
s390/qeth: fix use-after-free in hsci
KASAN found that addr was dereferenced after br2dev_event_work was freed.
BUG: KASAN: use-after-free in qeth_l2_br2dev_worker+0x5ba/0x6b0
Read of size 1 at addr 00000000fdcea440 by task kworker/u760:4/540
CPU: 17 PID: 540 Comm: kworker/u760:4 Tainted: G E 6.1.0-20221128.rc7.git1.5aa3bed4ce83.300.fc36.s390x+kasan #1
Hardware name: IBM 8561 T01 703 (LPAR)
Workqueue: 0.0.8000_event qeth_l2_br2dev_worker
Call Trace:
[] dump_stack_lvl+0xc6/0xf8
[] print_address_description.constprop.0+0x34/0x2a0
[] print_report+0x110/0x1f8
[] kasan_report+0xfc/0x128
[] qeth_l2_br2dev_worker+0x5ba/0x6b0
[] process_one_work+0x76e/0x1128
[] worker_thread+0x184/0x1098
[] kthread+0x26a/0x310
[] __ret_from_fork+0x8a/0xe8
[] ret_from_fork+0xa/0x40
Allocated by task 108338:
kasan_save_stack+0x40/0x68
kasan_set_track+0x36/0x48
__kasan_kmalloc+0xa0/0xc0
qeth_l2_switchdev_event+0x25a/0x738
atomic_notifier_call_chain+0x9c/0xf8
br_switchdev_fdb_notify+0xf4/0x110
fdb_notify+0x122/0x180
fdb_add_entry.constprop.0.isra.0+0x312/0x558
br_fdb_add+0x59e/0x858
rtnl_fdb_add+0x58a/0x928
rtnetlink_rcv_msg+0x5f8/0x8d8
netlink_rcv_skb+0x1f2/0x408
netlink_unicast+0x570/0x790
netlink_sendmsg+0x752/0xbe0
sock_sendmsg+0xca/0x110
____sys_sendmsg+0x510/0x6a8
___sys_sendmsg+0x12a/0x180
__sys_sendmsg+0xe6/0x168
__do_sys_socketcall+0x3c8/0x468
do_syscall+0x22c/0x328
__do_syscall+0x94/0xf0
system_call+0x82/0xb0
Freed by task 540:
kasan_save_stack+0x40/0x68
kasan_set_track+0x36/0x48
kasan_save_free_info+0x4c/0x68
____kasan_slab_free+0x14e/0x1a8
__kasan_slab_free+0x24/0x30
__kmem_cache_free+0x168/0x338
qeth_l2_br2dev_worker+0x154/0x6b0
process_one_work+0x76e/0x1128
worker_thread+0x184/0x1098
kthread+0x26a/0x310
__ret_from_fork+0x8a/0xe8
ret_from_fork+0xa/0x40
Last potentially related work creation:
kasan_save_stack+0x40/0x68
__kasan_record_aux_stack+0xbe/0xd0
insert_work+0x56/0x2e8
__queue_work+0x4ce/0xd10
queue_work_o
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= f7936b7b2663c99a096a5c432ba96ab1e91a6c0f < db6343a5b0d9661f2dd76f653c6d274d38234d2b | db6343a5b0d9661f2dd76f653c6d274d38234d2b |
| linux | linux | >= f7936b7b2663c99a096a5c432ba96ab1e91a6c0f < bde0dfc7c4569406a6ddeec363d04a1df7b3073f | bde0dfc7c4569406a6ddeec363d04a1df7b3073f |
| linux | linux | >= f7936b7b2663c99a096a5c432ba96ab1e91a6c0f < ebaaadc332cd21e9df4dcf9ce12552d9354bbbe4 | ebaaadc332cd21e9df4dcf9ce12552d9354bbbe4 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 5.15 < 5.15.83 | 5.15.83 |
| linux | linux_kernel | >= 5.16 < 6.0.13 | 6.0.13 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: s390/qeth: fix use-after-free in hsci
vendor_redhat·2024-10-21·CVSS 7.8
CVE-2022-48954 [HIGH] CWE-416 kernel: s390/qeth: fix use-after-free in hsci
kernel: s390/qeth: fix use-after-free in hsci
In the Linux kernel, the following vulnerability has been resolved:
s390/qeth: fix use-after-free in hsci
KASAN found that addr was dereferenced after br2dev_event_work was freed.
BUG: KASAN: use-after-free in qeth_l2_br2dev_worker+0x5ba/0x6b0
Read of size 1 at addr 00000000fdcea440 by task kworker/u760:4/540
CPU: 17 PID: 540 Comm: kworker/u760:4 Tainted: G E 6.1.0-20221128.rc7.git1.5aa3bed4ce83.300.fc36.s390x+kasan #1
Hardware name: IBM 8561 T01 703 (LPAR)
Workqueue: 0.0.8000_event qeth_l2_br2dev_worker
Call Trace:
[] dump_stack_lvl+0xc6/0xf8
[] print_address_description.constprop.0+0x34/0x2a0
[] print_report+0x110/0x1f8
[] kasan_report+0xfc/0x128
[] qeth_l2_br2dev_worker+0x5ba/0x6b0
[] process_one_work+0x76e/0x1128
[] worker_thread+0x184/0x1
Debian
CVE-2022-48954: linux - In the Linux kernel, the following vulnerability has been resolved: s390/qeth: ...
vendor_debian·2022·CVSS 7.8
CVE-2022-48954 [HIGH] CVE-2022-48954: linux - In the Linux kernel, the following vulnerability has been resolved: s390/qeth: ...
In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after br2dev_event_work was freed. ================================================================== BUG: KASAN: use-after-free in qeth_l2_br2dev_worker+0x5ba/0x6b0 Read of size 1 at addr 00000000fdcea440 by task kworker/u760:4/540 CPU: 17 PID: 540 Comm: kworker/u760:4 Tainted: G E 6.1.0-20221128.rc7.git1.5aa3bed4ce83.300.fc36.s390x+kasan #1 Hardware name: IBM 8561 T01 703 (LPAR) Workqueue: 0.0.8000_event qeth_l2_br2dev_worker Call Trace: [] dump_stack_lvl+0xc6/0xf8 [] print_address_description.constprop.0+0x34/0x2a0 [] print_report+0x110/0x1f8 [] kasan_report+0xfc/0x128 [] qeth_l2_br2dev_worker+0x5ba/0x6b0 [] process_one_work+0x76e/0x1128 [] wor
GHSA
GHSA-pvfv-p8r5-hrcw: In the Linux kernel, the following vulnerability has been resolved:
s390/qeth: fix use-after-free in hsci
KASAN found that addr was dereferenced aft
ghsa_unreviewed·2024-10-21
CVE-2022-48954 [HIGH] CWE-416 GHSA-pvfv-p8r5-hrcw: In the Linux kernel, the following vulnerability has been resolved:
s390/qeth: fix use-after-free in hsci
KASAN found that addr was dereferenced aft
In the Linux kernel, the following vulnerability has been resolved:
s390/qeth: fix use-after-free in hsci
KASAN found that addr was dereferenced after br2dev_event_work was freed.
BUG: KASAN: use-after-free in qeth_l2_br2dev_worker+0x5ba/0x6b0
Read of size 1 at addr 00000000fdcea440 by task kworker/u760:4/540
CPU: 17 PID: 540 Comm: kworker/u760:4 Tainted: G E 6.1.0-20221128.rc7.git1.5aa3bed4ce83.300.fc36.s390x+kasan #1
Hardware name: IBM 8561 T01 703 (LPAR)
Workqueue: 0.0.8000_event qeth_l2_br2dev_worker
Call Trace:
[] dump_stack_lvl+0xc6/0xf8
[] print_address_description.constprop.0+0x34/0x2a0
[] print_report+0x110/0x1f8
[] kasan_report+0xfc/0x128
[] qeth_l2_br2dev_worker+0x5ba/0x6b0
[] process_one_work+0x76e/0x1128
[] worker_thread+0x184/0x1098
[] kthread+0x26a/0x310
[] __ret_from_for
OSV
CVE-2022-48954: In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after
osv·2024-10-21·CVSS 7.8
CVE-2022-48954 [HIGH] CVE-2022-48954: In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after
In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after br2dev_event_work was freed. ================================================================== BUG: KASAN: use-after-free in qeth_l2_br2dev_worker+0x5ba/0x6b0 Read of size 1 at addr 00000000fdcea440 by task kworker/u760:4/540 CPU: 17 PID: 540 Comm: kworker/u760:4 Tainted: G E 6.1.0-20221128.rc7.git1.5aa3bed4ce83.300.fc36.s390x+kasan #1 Hardware name: IBM 8561 T01 703 (LPAR) Workqueue: 0.0.8000_event qeth_l2_br2dev_worker Call Trace: [] dump_stack_lvl+0xc6/0xf8 [] print_address_description.constprop.0+0x34/0x2a0 [] print_report+0x110/0x1f8 [] kasan_report+0xfc/0x128 [] qeth_l2_br2dev_worker+0x5ba/0x6b0 [] process_one_work+0x76e/0x1128 [] wor
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-21
Published