CVE-2022-49085: drbd: Fix five use after free bugs in get_initial_state
In the Linux kernel, the following vulnerability has been resolved:
drbd: Fix five use after free bugs in getinitialstate
In getinitialstate, it calls notifyinitialstatedone(skb,..) if cb->args[5]==1. If genlmsgput() failed in notifyinitialstatedone(), the skb will be freed by nlmsgfree(skb). Then getinitialstate will goto out and the freed skb will be used by return value skb->len, which is a uaf bug.
What's worse, the same problem goes even further: skb can also be freed in the notifystatechange -> notifystate calls below. Thus 4 additional uaf bugs happened.
My patch lets the problem callee functions: notifyinitialstatedone and notifystatechange return an error code if errors happen. So that the error codes could be propagated and the uaf bugs can be avoid.
v2 reports a compilation warning. This v3 fixed this warning and built successfully in my local environment with no additional warnings. v2: https://lore.kernel.org/patchwork/patch/1435218/
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-49085?
CVE-2022-49085 is classified as a use-after-free vulnerability which can lead to denial of service or potential code execution.
How do I fix CVE-2022-49085?
To fix CVE-2022-49085, you should update your Linux kernel to a version that includes the security patch addressing this vulnerability.
Which versions of the Linux kernel are affected by CVE-2022-49085?
CVE-2022-49085 affects Linux kernel versions prior to 5.18-rc1, specifically versions from 4.5 up to 5.17.3.
What are the potential impacts of CVE-2022-49085?
The potential impacts of CVE-2022-49085 include system crashes, denial of service, and possible remote code execution.
Where can I find more information on CVE-2022-49085?
More information about CVE-2022-49085 can be found in Linux kernel security advisory notices and related technical documentation.