cbcvebase.
CVE-2022-49315
published 2025-02-26

CVE-2022-49315: In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8192e: Fix deadlock in rtllib_beacons_stop() There is a deadlock in…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8192e: Fix deadlock in rtllib_beacons_stop() There is a deadlock in rtllib_beacons_stop(), which is shown below: (Thread 1) | (Thread 2) | rtllib_send_beacon() rtllib_beacons_stop() | mod_timer() spin_lock_irqsave() //(1) | (wait a time) ... | rtllib_send_beacon_cb() del_timer_sync() | spin_lock_irqsave() //(2) (wait timer to stop) | ... We hold ieee->beacon_lock in position (1) of thread 1 and use del_timer_sync() to wait timer to stop, but timer handler also need ieee->beacon_lock in position (2) of thread 2. As a result, rtllib_beacons_stop() will block forever. This patch extracts del_timer_sync() from the protection of spin_lock_irqsave(), which could let timer handler to obtain the needed lock.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < 4681129fda9e8555392eaaadb239ec6a6e2b3e124681129fda9e8555392eaaadb239ec6a6e2b3e12
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < 381045dc64d23a2229c47c5524c06bfc33d34446381045dc64d23a2229c47c5524c06bfc33d34446
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < 08bacf871c019163ccd1389d0bc957a43324967a08bacf871c019163ccd1389d0bc957a43324967a
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < 64b05fa212c7e4d057676e8b7e7120c6eb2f615b64b05fa212c7e4d057676e8b7e7120c6eb2f615b
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < 0f69d7d5e918aa43423d86bd17ddb11b1b5e8ada0f69d7d5e918aa43423d86bd17ddb11b1b5e8ada
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < fef451f0fbbe85dbd2962b18379d02e2965610dbfef451f0fbbe85dbd2962b18379d02e2965610db
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < 46c861009bf437a18417df24cea0d181741b7d7246c861009bf437a18417df24cea0d181741b7d72
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < ffd4c4d5293e4985092ea45ba21cad9326e2e434ffd4c4d5293e4985092ea45ba21cad9326e2e434
linuxlinux>= 94a799425eee8225a1e3fbe5f473d2ef04002577 < 9b6bdbd9337de3917945847bde262a34a87a63039b6bdbd9337de3917945847bde262a34a87a6303
linuxlinux_kernel< 4.9.3184.9.318
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 4.10 < 4.14.2834.14.283
linuxlinux_kernel>= 4.15 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.475.15.47
linuxlinux_kernel>= 5.16 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4
linuxlinux_kernel>= 5.5 < 5.10.1225.10.122

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.