CVE-2022-49925: RDMA/core: Fix null-ptr-deref in ib_core_cleanup()
In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Fix null-ptr-deref in ibcorecleanup()
KASAN reported a null-ptr-deref error:
KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f] CPU: 1 PID: 379 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) RIP: 0010:destroyworkqueue+0x2f/0x740 RSP: 0018:ffff888016137df8 EFLAGS: 00000202 ... Call Trace: ibcorecleanup+0xa/0xa1 [ibcore] dosysdeletemodule.constprop.0+0x34f/0x5b0 dosyscall64+0x3a/0x90 entrySYSCALL64afterhwframe+0x63/0xcd RIP: 0033:0x7fa1a0d221b7 ...
It is because the fail of rocegidmgmtinit() is ignored:
ibcoreinit() rocegidmgmtinit() gidcachewq = allocorderedworkqueue # fail ... ibcorecleanup() rocegidmgmtcleanup() destroyworkqueue(gidcachewq) # destroy an unallocated wq
Fix this by catching the fail of rocegidmgmtinit() in ibcoreinit().
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-49925?
CVE-2022-49925 is classified as a medium severity vulnerability in the Linux kernel.
What impact does CVE-2022-49925 have on systems running affected versions of the Linux kernel?
CVE-2022-49925 can lead to a null pointer dereference, potentially causing system crashes or instability.
How do I fix CVE-2022-49925?
To fix CVE-2022-49925, upgrade to the latest version of the Linux kernel that includes the patch addressing this vulnerability.
Which versions of the Linux kernel are affected by CVE-2022-49925?
CVE-2022-49925 affects multiple versions of the Linux kernel before the patch was applied.
Is there a workaround for CVE-2022-49925 if I cannot immediately upgrade my Linux kernel?
Currently, there are no known effective workarounds for CVE-2022-49925; upgrading is recommended.