CVE-2022-49407
published 2025-02-26CVE-2022-49407: In the Linux kernel, the following vulnerability has been resolved: dlm: fix plock invalid read This patch fixes an invalid read showed by KASAN. A unlock will…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.30%
22.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
dlm: fix plock invalid read
This patch fixes an invalid read showed by KASAN. A unlock will allocate a
"struct plock_op" and a followed send_op() will append it to a global
send_list data structure. In some cases a followed dev_read() moves it
to recv_list and dev_write() will cast it to "struct plock_xop" and access
fields which are only available in those structures. At this point an
invalid read happens by accessing those fields.
To fix this issue the "callback" field is moved to "struct plock_op" to
indicate that a cast to "plock_xop" is allowed and does the additional
"plock_xop" handling if set.
Example of the KASAN output which showed the invalid read:
[ 2064.296453] ==================================================================
[ 2064.304852] BUG: KASAN: slab-out-of-bounds in dev_write+0x52b/0x5a0 [dlm]
[ 2064.306491] Read of size 8 at addr ffff88800ef227d8 by task dlm_controld/7484
[ 2064.308168]
[ 2064.308575] CPU: 0 PID: 7484 Comm: dlm_controld Kdump: loaded Not tainted 5.14.0+ #9
[ 2064.310292] Hardware name: Red Hat KVM, BIOS 0.5.1 01/01/2011
[ 2064.311618] Call Trace:
[ 2064.312218] dump_stack_lvl+0x56/0x7b
[ 2064.313150] print_address_description.constprop.8+0x21/0x150
[ 2064.314578] ? dev_write+0x52b/0x5a0 [dlm]
[ 2064.315610] ? dev_write+0x52b/0x5a0 [dlm]
[ 2064.316595] kasan_report.cold.14+0x7f/0x11b
[ 2064.317674] ? dev_write+0x52b/0x5a0 [dlm]
[ 2064.318687] dev_write+0x52b/0x5a0 [dlm]
[ 2064.319629] ? dev_read+0x4a0/0x4a0 [dlm]
[ 2064.320713] ? bpf_lsm_kernfs_init_security+0x10/0x10
[ 2064.321926] vfs_write+0x17e/0x930
[ 2064.322769] ? __fget_light+0x1aa/0x220
[ 2064.323753] ksys_write+0xf1/0x1c0
[ 2064.324548] ? __ia32_sys_read+0xb0/0xb0
[ 2064.325464] do_syscall_64+0x3a/0x80
[ 2064.326387] entry_SYSCALL_64_after_hwframe+0x44/0xae
[ 2064.327606] RIP: 0033:0x7f807e4ba96f
[ 2064.328470] Code: 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 39 87 f8 ff 48 8b 54 24 18 48 8b 74 24
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < 2c55155cc365861044d9e6e80e342693e8805e33 | 2c55155cc365861044d9e6e80e342693e8805e33 |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < 72f2f68970f9bdc252d59e119b385a6441b0b155 | 72f2f68970f9bdc252d59e119b385a6441b0b155 |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < 5a1765adf9855cf0f6d3f7e0eb4b78ca66f70dee | 5a1765adf9855cf0f6d3f7e0eb4b78ca66f70dee |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < 49cd9eb7b9a7b88124b31e31f8e539acaf1b3a6d | 49cd9eb7b9a7b88124b31e31f8e539acaf1b3a6d |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < 899bc4429174861122f0c236588700a4710c1fec | 899bc4429174861122f0c236588700a4710c1fec |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < acdad5bc9827922ec2f2e84fd198718aa8e8ab92 | acdad5bc9827922ec2f2e84fd198718aa8e8ab92 |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < 56aa8d1fbd02357f3bf81bdfba1cde87ce8402fc | 56aa8d1fbd02357f3bf81bdfba1cde87ce8402fc |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < e421872fa17542cf33747071fb141b0130ce9ef7 | e421872fa17542cf33747071fb141b0130ce9ef7 |
| linux | linux | >= 586759f03e2e9031ac5589912a51a909ed53c30a < 42252d0d2aa9b94d168241710a761588b3959019 | 42252d0d2aa9b94d168241710a761588b3959019 |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 2.6.22 < 4.9.318 | 4.9.318 |
| linux | linux_kernel | >= 4.10 < 4.14.283 | 4.14.283 |
| linux | linux_kernel | >= 4.15 < 4.19.247 | 4.19.247 |
| linux | linux_kernel | >= 4.20 < 5.4.198 | 5.4.198 |
| linux | linux_kernel | >= 5.11 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
| linux | linux_kernel | >= 5.5 < 5.10.121 | 5.10.121 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: dlm: fix plock invalid read
vendor_redhat·2025-02-26·CVSS 7.1
CVE-2022-49407 [HIGH] CWE-125 kernel: dlm: fix plock invalid read
kernel: dlm: fix plock invalid read
In the Linux kernel, the following vulnerability has been resolved:
dlm: fix plock invalid read
This patch fixes an invalid read showed by KASAN. A unlock will allocate a
"struct plock_op" and a followed send_op() will append it to a global
send_list data structure. In some cases a followed dev_read() moves it
to recv_list and dev_write() will cast it to "struct plock_xop" and access
fields which are only available in those structures. At this point an
invalid read happens by accessing those fields.
To fix this issue the "callback" field is moved to "struct plock_op" to
indicate that a cast to "plock_xop" is allowed and does the additional
"plock_xop" handling if set.
Example of the KASAN output which showed the invalid read:
[ 2064.296453] ============
Debian
CVE-2022-49407: linux - In the Linux kernel, the following vulnerability has been resolved: dlm: fix pl...
vendor_debian·2022·CVSS 7.1
CVE-2022-49407 [HIGH] CVE-2022-49407: linux - In the Linux kernel, the following vulnerability has been resolved: dlm: fix pl...
In the Linux kernel, the following vulnerability has been resolved: dlm: fix plock invalid read This patch fixes an invalid read showed by KASAN. A unlock will allocate a "struct plock_op" and a followed send_op() will append it to a global send_list data structure. In some cases a followed dev_read() moves it to recv_list and dev_write() will cast it to "struct plock_xop" and access fields which are only available in those structures. At this point an invalid read happens by accessing those fields. To fix this issue the "callback" field is moved to "struct plock_op" to indicate that a cast to "plock_xop" is allowed and does the additional "plock_xop" handling if set. Example of the KASAN output which showed the invalid read: [ 2064.296453] =================================================
GHSA
GHSA-vgg3-rg3w-f5j6: In the Linux kernel, the following vulnerability has been resolved:
dlm: fix plock invalid read
This patch fixes an invalid read showed by KASAN
ghsa_unreviewed·2025-09-22
CVE-2022-49407 [HIGH] CWE-125 GHSA-vgg3-rg3w-f5j6: In the Linux kernel, the following vulnerability has been resolved:
dlm: fix plock invalid read
This patch fixes an invalid read showed by KASAN
In the Linux kernel, the following vulnerability has been resolved:
dlm: fix plock invalid read
This patch fixes an invalid read showed by KASAN. A unlock will allocate a
"struct plock_op" and a followed send_op() will append it to a global
send_list data structure. In some cases a followed dev_read() moves it
to recv_list and dev_write() will cast it to "struct plock_xop" and access
fields which are only available in those structures. At this point an
invalid read happens by accessing those fields.
To fix this issue the "callback" field is moved to "struct plock_op" to
indicate that a cast to "plock_xop" is allowed and does the additional
"plock_xop" handling if set.
Example of the KASAN output which showed the invalid read:
[ 2064.296453] ============================================
OSV
CVE-2022-49407: In the Linux kernel, the following vulnerability has been resolved: dlm: fix plock invalid read This patch fixes an invalid read showed by KASAN
osv·2025-02-26·CVSS 7.1
CVE-2022-49407 [HIGH] CVE-2022-49407: In the Linux kernel, the following vulnerability has been resolved: dlm: fix plock invalid read This patch fixes an invalid read showed by KASAN
In the Linux kernel, the following vulnerability has been resolved: dlm: fix plock invalid read This patch fixes an invalid read showed by KASAN. A unlock will allocate a "struct plock_op" and a followed send_op() will append it to a global send_list data structure. In some cases a followed dev_read() moves it to recv_list and dev_write() will cast it to "struct plock_xop" and access fields which are only available in those structures. At this point an invalid read happens by accessing those fields. To fix this issue the "callback" field is moved to "struct plock_op" to indicate that a cast to "plock_xop" is allowed and does the additional "plock_xop" handling if set. Example of the KASAN output which showed the invalid read: [ 2064.296453] =================================================
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2c55155cc365861044d9e6e80e342693e8805e33https://git.kernel.org/stable/c/42252d0d2aa9b94d168241710a761588b3959019https://git.kernel.org/stable/c/49cd9eb7b9a7b88124b31e31f8e539acaf1b3a6dhttps://git.kernel.org/stable/c/56aa8d1fbd02357f3bf81bdfba1cde87ce8402fchttps://git.kernel.org/stable/c/5a1765adf9855cf0f6d3f7e0eb4b78ca66f70deehttps://git.kernel.org/stable/c/72f2f68970f9bdc252d59e119b385a6441b0b155https://git.kernel.org/stable/c/899bc4429174861122f0c236588700a4710c1fechttps://git.kernel.org/stable/c/acdad5bc9827922ec2f2e84fd198718aa8e8ab92https://git.kernel.org/stable/c/e421872fa17542cf33747071fb141b0130ce9ef7
2025-02-26
Published