CVE-2022-49905: net/smc: Fix possible leaked pernet namespace in smc_init()
In the Linux kernel, the following vulnerability has been resolved:
net/smc: Fix possible leaked pernet namespace in smcinit()
In smcinit(), registerpernetsubsys(&smcnetstatops) is called without any error handling. If it fails, registering of &smcnetops won't be reverted. And if smcnlinit() fails, &smcnetstatops itself won't be reverted.
This leaves wild ops in subsystem linkedlist and when another module tries to call registerpernetoperations() it triggers page fault:
BUG: unable to handle page fault for address: fffffbfff81b964c RIP: 0010:registerpernetoperations+0x1b9/0x5f0 Call Trace: <TASK> registerpernetsubsys+0x29/0x40 ebtablesinit+0x58/0x1000 [ebtables] ...
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-49905?
The severity of CVE-2022-49905 is categorized as medium due to the potential for namespace leakage.
How do I fix CVE-2022-49905?
To fix CVE-2022-49905, ensure you update your Linux kernel to the latest patched version.
Which versions of the Linux Kernel are affected by CVE-2022-49905?
CVE-2022-49905 affects multiple versions of the Linux kernel, particularly those before the patch was applied.
What component of the Linux Kernel does CVE-2022-49905 impact?
CVE-2022-49905 impacts the SMC (Shared Memory Communication) initialization component of the Linux kernel.
Is CVE-2022-49905 exploitable remotely?
CVE-2022-49905 is generally not considered exploitable remotely since it requires local access to affect the namespace.