目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2022-48925— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.22% · P13

影响版本矩阵 10

厂商产品版本范围状态
LinuxLinux732d41c545bb359cbb8c94698bdc1f8bcf82279c< 5b1cef5798b4fd6e4fd5522e7b8a26248beeacaaaffected
732d41c545bb359cbb8c94698bdc1f8bcf82279c< 00265efbd3e5705038c9492a434fda8cf960c8a2affected
732d41c545bb359cbb8c94698bdc1f8bcf82279c< d350724795c7a48b05bf921d94699fbfecf7da0baffected
732d41c545bb359cbb8c94698bdc1f8bcf82279c< 22e9f71072fa605cbf033158db58e0790101928daffected
5.10affected
< 5.10unaffected
5.10.103≤ 5.10.*unaffected
5.15.26≤ 5.15.*unaffected
… +2 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2022-48925 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
RDMA/cma: Do not change route.addr.src_addr outside state checks
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Do not change route.addr.src_addr outside state checks If the state is not idle then resolve_prepare_src() should immediately fail and no change to global state should happen. However, it unconditionally overwrites the src_addr trying to build a temporary any address. For instance if the state is already RDMA_CM_LISTEN then this will corrupt the src_addr and would cause the test in cma_cancel_operation(): if (cma_any_addr(cma_src_addr(id_priv)) && !id_priv->cma_dev) Which would manifest as this trace from syzkaller: BUG: KASAN: use-after-free in __list_add_valid+0x93/0xa0 lib/list_debug.c:26 Read of size 8 at addr ffff8881546491e0 by task syz-executor.1/32204 CPU: 1 PID: 32204 Comm: syz-executor.1 Not tainted 5.12.0-rc8-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:79 [inline] dump_stack+0x141/0x1d7 lib/dump_stack.c:120 print_address_description.constprop.0.cold+0x5b/0x2f8 mm/kasan/report.c:232 __kasan_report mm/kasan/report.c:399 [inline] kasan_report.cold+0x7c/0xd8 mm/kasan/report.c:416 __list_add_valid+0x93/0xa0 lib/list_debug.c:26 __list_add include/linux/list.h:67 [inline] list_add_tail include/linux/list.h:100 [inline] cma_listen_on_all drivers/infiniband/core/cma.c:2557 [inline] rdma_listen+0x787/0xe00 drivers/infiniband/core/cma.c:3751 ucma_listen+0x16a/0x210 drivers/infiniband/core/ucma.c:1102 ucma_write+0x259/0x350 drivers/infiniband/core/ucma.c:1732 vfs_write+0x28e/0xa30 fs/read_write.c:603 ksys_write+0x1ee/0x250 fs/read_write.c:658 do_syscall_64+0x2d/0x70 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x44/0xae This is indicating that an rdma_id_private was destroyed without doing cma_cancel_listens(). Instead of trying to re-use the src_addr memory to indirectly create an any address derived from the dst build one explicitly on the stack and bind to that as any other normal flow would do. rdma_bind_addr() will copy it over the src_addr once it knows the state is valid. This is similar to commit bc0bdc5afaa7 ("RDMA/cma: Do not change route.addr.src_addr.ss_family")
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于当状态不是空闲时,会无条件地覆盖src_addr。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 732d41c545bb359cbb8c94698bdc1f8bcf82279c ~ 5b1cef5798b4fd6e4fd5522e7b8a26248beeacaa -
LinuxLinux 5.10 -

二、漏洞 CVE-2022-48925 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2022-48925 的情报信息

登录查看更多情报信息。

CVE-2022-48925 其他参考 (4)

同批安全公告 · Linux · 2024-08-22 · 共 42 条

CVE-2022-489418.8 HIGHLinux kernel 竞争条件问题漏洞
CVE-2022-489198.8 HIGHLinux kernel 安全漏洞
CVE-2022-489237.8 HIGHLinux kernel 安全漏洞
CVE-2022-489277.8 HIGHLinux kernel 安全漏洞
CVE-2022-489137.8 HIGHLinux kernel 安全漏洞
CVE-2022-489127.8 HIGHLinux kernel 安全漏洞
CVE-2022-489117.8 HIGHLinux kernel 安全漏洞
CVE-2022-489327.8 HIGHLinux kernel 安全漏洞
CVE-2022-489357.8 HIGHLinux kernel 安全漏洞
CVE-2022-489407.8 HIGHLinux kernel 缓冲区错误漏洞
CVE-2022-489437.1 HIGHLinux kernel 安全漏洞
CVE-2022-48933Linux kernel 安全漏洞
CVE-2022-48934Linux kernel 安全漏洞
CVE-2022-48931Linux kernel 安全漏洞
CVE-2022-48937Linux kernel 安全漏洞
CVE-2022-48938Linux kernel 输入验证错误漏洞
CVE-2022-48930Linux kernel 安全漏洞
CVE-2022-48929Linux kernel 安全漏洞
CVE-2022-48928Linux kernel 安全漏洞
CVE-2022-48939Linux kernel 安全漏洞

显示前 20 条,共 42 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48925

暂无评论


发表评论