CVE-2022-49434
published 2025-02-26CVE-2022-49434: In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store() The sysfs…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
12.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
The sysfs sriov_numvfs_store() path acquires the device lock before the
config space access lock:
sriov_numvfs_store
device_lock # A (1) acquire device lock
sriov_configure
vfio_pci_sriov_configure # (for example)
vfio_pci_core_sriov_configure
pci_disable_sriov
sriov_disable
pci_cfg_access_lock
pci_wait_cfg # B (4) wait for dev->block_cfg_access == 0
Previously, pci_dev_lock() acquired the config space access lock before the
device lock:
pci_dev_lock
pci_cfg_access_lock
dev->block_cfg_access = 1 # B (2) set dev->block_cfg_access = 1
device_lock # A (3) wait for device lock
Any path that uses pci_dev_lock(), e.g., pci_reset_function(), may
deadlock with sriov_numvfs_store() if the operations occur in the sequence
(1) (2) (3) (4).
Avoid the deadlock by reversing the order in pci_dev_lock() so it acquires
the device lock before the config space access lock, the same as the
sriov_numvfs_store() path.
[bhelgaas: combined and adapted commit log from Jay Zhou's independent
subsequent posting:
https://lore.kernel.org/r/[email protected]]
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 17530e71e0166a37f8e20a9b7bcf1d50ae3cff8e < c3c6dc1853b8bf3c718f96fd8480a6eb09ba4831 | c3c6dc1853b8bf3c718f96fd8480a6eb09ba4831 |
| linux | linux | >= 17530e71e0166a37f8e20a9b7bcf1d50ae3cff8e < aed6d4d519210c28817948f34c53b6e058e0456c | aed6d4d519210c28817948f34c53b6e058e0456c |
| linux | linux | >= 17530e71e0166a37f8e20a9b7bcf1d50ae3cff8e < c9a81f9ed6ae3554621d6a50220b1bc74b67d81e | c9a81f9ed6ae3554621d6a50220b1bc74b67d81e |
| linux | linux | >= 17530e71e0166a37f8e20a9b7bcf1d50ae3cff8e < eff3587b9c01439b738298475e555c028ac9f55e | eff3587b9c01439b738298475e555c028ac9f55e |
| linux | linux | >= 17530e71e0166a37f8e20a9b7bcf1d50ae3cff8e < 2cdd5284035322795b0964f899eefba254cfe483 | 2cdd5284035322795b0964f899eefba254cfe483 |
| linux | linux | >= 17530e71e0166a37f8e20a9b7bcf1d50ae3cff8e < ea047f51172aa68841adef7f52d375002438b8f0 | ea047f51172aa68841adef7f52d375002438b8f0 |
| linux | linux | >= 17530e71e0166a37f8e20a9b7bcf1d50ae3cff8e < 59ea6b3ae51df7cd6bfd84c9c0030609b9315622 | 59ea6b3ae51df7cd6bfd84c9c0030609b9315622 |
| linux | linux | >= 17530e71e0166a37f8e20a9b7bcf1d50ae3cff8e < a91ee0e9fca9d7501286cfbced9b30a33e52740a | a91ee0e9fca9d7501286cfbced9b30a33e52740a |
| linux | linux_kernel | < 4.9.318 | 4.9.318 |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 4.10 < 4.14.283 | 4.14.283 |
| linux | linux_kernel | >= 4.15 < 4.19.247 | 4.19.247 |
| linux | linux_kernel | >= 4.20 < 5.4.198 | 5.4.198 |
| linux | linux_kernel | >= 5.11 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
| linux | linux_kernel | >= 5.5 < 5.10.121 | 5.10.121 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fxw3-5jmj-82p9: In the Linux kernel, the following vulnerability has been resolved:
PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
The sysfs sri
ghsa_unreviewed·2025-10-22
CVE-2022-49434 [MEDIUM] CWE-667 GHSA-fxw3-5jmj-82p9: In the Linux kernel, the following vulnerability has been resolved:
PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
The sysfs sri
In the Linux kernel, the following vulnerability has been resolved:
PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
The sysfs sriov_numvfs_store() path acquires the device lock before the
config space access lock:
sriov_numvfs_store
device_lock # A (1) acquire device lock
sriov_configure
vfio_pci_sriov_configure # (for example)
vfio_pci_core_sriov_configure
pci_disable_sriov
sriov_disable
pci_cfg_access_lock
pci_wait_cfg # B (4) wait for dev->block_cfg_access == 0
Previously, pci_dev_lock() acquired the config space access lock before the
device lock:
pci_dev_lock
pci_cfg_access_lock
dev->block_cfg_access = 1 # B (2) set dev->block_cfg_access = 1
device_lock # A (3) wait for device lock
Any path that uses pci_dev_lock(), e.g., pci_reset_function(), may
deadlock wit
OSV
CVE-2022-49434: In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store() The sysfs sriov
osv·2025-02-26·CVSS 5.5
CVE-2022-49434 [MEDIUM] CVE-2022-49434: In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store() The sysfs sriov
In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store() The sysfs sriov_numvfs_store() path acquires the device lock before the config space access lock: sriov_numvfs_store device_lock # A (1) acquire device lock sriov_configure vfio_pci_sriov_configure # (for example) vfio_pci_core_sriov_configure pci_disable_sriov sriov_disable pci_cfg_access_lock pci_wait_cfg # B (4) wait for dev->block_cfg_access == 0 Previously, pci_dev_lock() acquired the config space access lock before the device lock: pci_dev_lock pci_cfg_access_lock dev->block_cfg_access = 1 # B (2) set dev->block_cfg_access = 1 device_lock # A (3) wait for device lock Any path that uses pci_dev_lock(), e.g., pci_reset_function(), may deadlock with srio
Red Hat
kernel: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49434 [MEDIUM] kernel: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
kernel: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
In the Linux kernel, the following vulnerability has been resolved:
PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
The sysfs sriov_numvfs_store() path acquires the device lock before the
config space access lock:
sriov_numvfs_store
device_lock # A (1) acquire device lock
sriov_configure
vfio_pci_sriov_configure # (for example)
vfio_pci_core_sriov_configure
pci_disable_sriov
sriov_disable
pci_cfg_access_lock
pci_wait_cfg # B (4) wait for dev->block_cfg_access == 0
Previously, pci_dev_lock() acquired the config space access lock before the
device lock:
pci_dev_lock
pci_cfg_access_lock
dev->block_cfg_access = 1 # B (2) set dev->block_cfg_access = 1
device_lock # A (3) wait for device lock
Any path
Debian
CVE-2022-49434: linux - In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid ...
vendor_debian·2022·CVSS 5.5
CVE-2022-49434 [MEDIUM] CVE-2022-49434: linux - In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid ...
In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store() The sysfs sriov_numvfs_store() path acquires the device lock before the config space access lock: sriov_numvfs_store device_lock # A (1) acquire device lock sriov_configure vfio_pci_sriov_configure # (for example) vfio_pci_core_sriov_configure pci_disable_sriov sriov_disable pci_cfg_access_lock pci_wait_cfg # B (4) wait for dev->block_cfg_access == 0 Previously, pci_dev_lock() acquired the config space access lock before the device lock: pci_dev_lock pci_cfg_access_lock dev->block_cfg_access = 1 # B (2) set dev->block_cfg_access = 1 device_lock # A (3) wait for device lock Any path that uses pci_dev_lock(), e.g., pci_reset_function(), may deadlock with srio
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2cdd5284035322795b0964f899eefba254cfe483https://git.kernel.org/stable/c/59ea6b3ae51df7cd6bfd84c9c0030609b9315622https://git.kernel.org/stable/c/a91ee0e9fca9d7501286cfbced9b30a33e52740ahttps://git.kernel.org/stable/c/aed6d4d519210c28817948f34c53b6e058e0456chttps://git.kernel.org/stable/c/c3c6dc1853b8bf3c718f96fd8480a6eb09ba4831https://git.kernel.org/stable/c/c9a81f9ed6ae3554621d6a50220b1bc74b67d81ehttps://git.kernel.org/stable/c/ea047f51172aa68841adef7f52d375002438b8f0https://git.kernel.org/stable/c/eff3587b9c01439b738298475e555c028ac9f55e
2025-02-26
Published