目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2022-48840— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 理论可行 EPSS 0.24% · P15

影响版本矩阵 5

厂商产品版本范围状态
LinuxLinux85aa76066fef64de8a48d0da6b4071ceac455a94< 80974bb730270199c6fcb189af04d5945b87e813affected
7b9515172ab4d4c6ac0eae4b71013ee6ce932205< 4477b9a4193b35eb3a8afd2adf2d42add2f88d57affected
974578017fc1fdd06cea8afb9dfa32602e8529ed< b04683ff8f0823b869c219c78ba0d974bddea0b5affected
5.15.27< 5.15.31affected
5.16.13< 5.16.17affected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2022-48840 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
iavf: Fix hang during reboot/shutdown
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iavf: Fix hang during reboot/shutdown Recent commit 974578017fc1 ("iavf: Add waiting so the port is initialized in remove") adds a wait-loop at the beginning of iavf_remove() to ensure that port initialization is finished prior unregistering net device. This causes a regression in reboot/shutdown scenario because in this case callback iavf_shutdown() is called and this callback detaches the device, makes it down if it is running and sets its state to __IAVF_REMOVE. Later shutdown callback of associated PF driver (e.g. ice_shutdown) is called. That callback calls among other things sriov_disable() that calls indirectly iavf_remove() (see stack trace below). As the adapter state is already __IAVF_REMOVE then the mentioned loop is end-less and shutdown process hangs. The patch fixes this by checking adapter's state at the beginning of iavf_remove() and skips the rest of the function if the adapter is already in remove state (shutdown is in progress). Reproducer: 1. Create VF on PF driven by ice or i40e driver 2. Ensure that the VF is bound to iavf driver 3. Reboot [52625.981294] sysrq: SysRq : Show Blocked State [52625.988377] task:reboot state:D stack: 0 pid:17359 ppid: 1 f2 [52625.996732] Call Trace: [52625.999187] __schedule+0x2d1/0x830 [52626.007400] schedule+0x35/0xa0 [52626.010545] schedule_hrtimeout_range_clock+0x83/0x100 [52626.020046] usleep_range+0x5b/0x80 [52626.023540] iavf_remove+0x63/0x5b0 [iavf] [52626.027645] pci_device_remove+0x3b/0xc0 [52626.031572] device_release_driver_internal+0x103/0x1f0 [52626.036805] pci_stop_bus_device+0x72/0xa0 [52626.040904] pci_stop_and_remove_bus_device+0xe/0x20 [52626.045870] pci_iov_remove_virtfn+0xba/0x120 [52626.050232] sriov_disable+0x2f/0xe0 [52626.053813] ice_free_vfs+0x7c/0x340 [ice] [52626.057946] ice_remove+0x220/0x240 [ice] [52626.061967] ice_shutdown+0x16/0x50 [ice] [52626.065987] pci_device_shutdown+0x34/0x60 [52626.070086] device_shutdown+0x165/0x1c5 [52626.074011] kernel_restart+0xe/0x30 [52626.077593] __do_sys_reboot+0x1d2/0x210 [52626.093815] do_syscall_64+0x5b/0x1a0 [52626.097483] entry_SYSCALL_64_after_hwframe+0x65/0xca
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于iavf模块中发现重启/关机时的挂起问题。在iavf_remove函数中添加的等待循环可能会导致重启或关机时的死循环。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 85aa76066fef64de8a48d0da6b4071ceac455a94 ~ 80974bb730270199c6fcb189af04d5945b87e813 -
LinuxLinux 5.15.27 ~ 5.15.31 -

二、漏洞 CVE-2022-48840 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2022-48840 的情报信息

登录查看更多情报信息。

CVE-2022-48840 其他参考 (3)

同批安全公告 · Linux · 2024-07-16 · 共 98 条

CVE-2022-487889.8 CRITICALLinux kernel 安全漏洞
CVE-2022-487899.8 CRITICALLinux kernel 安全漏洞
CVE-2022-488519.8 CRITICALLinux kernel 安全漏洞
CVE-2022-487909.8 CRITICALLinux kernel 安全漏洞
CVE-2022-488299.1 CRITICALLinux kernel 安全漏洞
CVE-2022-488289.1 CRITICALLinux kernel 安全漏洞
CVE-2022-487858.8 HIGHLinux kernel 安全漏洞
CVE-2022-487828.8 HIGHLinux kernel 安全漏洞
CVE-2022-488308.8 HIGHLinux kernel 安全漏洞
CVE-2022-488648.8 HIGHLinux kernel 安全漏洞
CVE-2022-487917.8 HIGHLinux kernel 安全漏洞
CVE-2022-487927.8 HIGHLinux kernel 安全漏洞
CVE-2022-488477.8 HIGHLinux kernel 安全漏洞
CVE-2022-488397.8 HIGHLinux kernel 安全漏洞
CVE-2022-488227.8 HIGHLinux kernel 安全漏洞
CVE-2022-488217.8 HIGHLinux kernel 安全漏洞
CVE-2022-488167.8 HIGHLinux kernel 安全漏洞
CVE-2022-487967.8 HIGHLinux kernel 安全漏洞
CVE-2022-488017.8 HIGHLinux kernel 安全漏洞
CVE-2024-410087.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 98 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48840

暂无评论


发表评论