Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-49309— drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback()

AI Predicted 5.5 Difficulty: Moderate EPSS 0.19% · P10

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinuxfb127a61c9d8dfd9b370ee173344d01711f3c698< c84e5c819600ee0628f61b33d145258ae0f3d7a7affected
fb127a61c9d8dfd9b370ee173344d01711f3c698< f89f6c3ebf69623b8ea48200bd690e9e210335a1affected
fb127a61c9d8dfd9b370ee173344d01711f3c698< ce129d3efd181da5fd56f4360cc8827122afa67eaffected
fb127a61c9d8dfd9b370ee173344d01711f3c698< 2c41f5c341853f84b7bc2f32605d4e2782e8c279affected
fb127a61c9d8dfd9b370ee173344d01711f3c698< cc7ad0d77b51c872d629bcd98aea463a3c4109e7affected
5.10affected
< 5.10unaffected
5.10.237≤ 5.10.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-49309

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback() There is a deadlock in rtw_surveydone_event_callback(), which is shown below: (Thread 1) | (Thread 2) | _set_timer() rtw_surveydone_event_callback()| mod_timer() spin_lock_bh() //(1) | (wait a time) ... | rtw_scan_timeout_handler() del_timer_sync() | spin_lock_bh() //(2) (wait timer to stop) | ... We hold pmlmepriv->lock in position (1) of thread 1 and use del_timer_sync() to wait timer to stop, but timer handler also need pmlmepriv->lock in position (2) of thread 2. As a result, rtw_surveydone_event_callback() will block forever. This patch extracts del_timer_sync() from the protection of spin_lock_bh(), which could let timer handler to obtain the needed lock. What`s more, we change spin_lock_bh() in rtw_scan_timeout_handler() to spin_lock_irq(). Otherwise, spin_lock_bh() will also cause deadlock() in timer handler.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于staging rtl8723bs驱动中rtw_surveydone_event_callback函数存在死锁。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux fb127a61c9d8dfd9b370ee173344d01711f3c698 ~ c84e5c819600ee0628f61b33d145258ae0f3d7a7 -
LinuxLinux 5.10 -

II. Public POCs for CVE-2022-49309

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-49309

登录查看更多情报信息。

Patches & Fixes for CVE-2022-49309 (5)

Same Patch Batch · Linux · 2025-02-26 · 706 CVEs total

CVE-2022-491499.8 CRITICALrxrpc: Fix call timer start racing with call destruction
CVE-2022-495619.8 CRITICALnetfilter: conntrack: re-fetch conntrack after insertion
CVE-2022-494079.8 CRITICALdlm: fix plock invalid read
CVE-2022-493629.8 CRITICALNFSD: Fix potential use-after-free in nfsd_file_put()
CVE-2022-492809.8 CRITICALNFSD: prevent underflow in nfssvc_decode_writeargs()
CVE-2022-493569.8 CRITICALSUNRPC: Trap RDMA segment overflows
CVE-2022-494189.8 CRITICALNFSv4: Fix free of uninitialized nfs4_label on referral lookup.
CVE-2022-490949.8 CRITICALnet/tls: fix slab-out-of-bounds bug in decrypt_internal
CVE-2022-490939.8 CRITICALskbuff: fix coalescing for page_pool fragment recycling
CVE-2022-492609.8 CRITICALcrypto: hisilicon/sec - fix the aead software fallback for engine
CVE-2022-491949.8 CRITICALnet: bcmgenet: Use stronger register read/writes to assure ordering
CVE-2022-492019.8 CRITICALibmvnic: fix race between xmit and reset
CVE-2022-490589.1 CRITICALcifs: potential buffer overflow in handling symlinks
CVE-2022-495358.8 HIGHscsi: lpfc: Fix null pointer dereference after failing to issue FLOGI and PLOGI
CVE-2022-491598.8 HIGHscsi: qla2xxx: Implement ref count for SRB
CVE-2022-491388.8 HIGHBluetooth: hci_event: Ignore multiple conn complete events
CVE-2022-494798.8 HIGHmt76: fix tx status related use-after-free race on station removal
CVE-2022-494708.8 HIGHBluetooth: btmtksdio: fix use-after-free at btmtksdio_recv_event
CVE-2022-491118.8 HIGHBluetooth: Fix use after free in hci_send_acl
CVE-2022-491148.8 HIGHscsi: libfc: Fix use after free in fc_exch_abts_resp()

Showing top 20 of 706 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-49309

No comments yet


Leave a comment