CVE-2022-48816: SUNRPC: lock against ->sock changing during sysfs read
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: lock against ->sock changing during sysfs read
->sock can be set to NULL asynchronously unless ->recvmutex is held. So it is important to hold that mutex. Otherwise a sysfs read can trigger an oops. Commit 17f09d3f619a ("SUNRPC: Check if the xprt is connected before handling sysfs reads") appears to attempt to fix this problem, but it only narrows the race window.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.16.10 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.17 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 17f09d3f619a - Compensating control
Ensure the SUNRPC receive mutex (->recv_mutex) is held when accessing the transport socket (->sock) so that ->sock is not set to NULL asynchronously during sysfs reads.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-48816?
CVE-2022-48816 is classified as a high severity vulnerability due to the potential for concurrent access issues in the Linux kernel.
How do I fix CVE-2022-48816?
To fix CVE-2022-48816, upgrade the Linux kernel to version 5.16.10 or 5.17 as specified in the advisory.
What systems are affected by CVE-2022-48816?
CVE-2022-48816 affects specific versions of the Linux kernel in various distributions, particularly those managed by Red Hat.
What are the potential consequences of CVE-2022-48816?
The potential consequences of CVE-2022-48816 include system instability and the risk of data corruption due to improper locking mechanisms.
Is there a workaround for CVE-2022-48816?
While the recommended solution is to upgrade, a temporary workaround could involve ensuring that the recv_mutex is held during sysfs read operations.