CVE-2022-49390
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
26/02/2025
Last modified:
25/03/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
macsec: fix UAF bug for real_dev<br />
<br />
Create a new macsec device but not get reference to real_dev. That can<br />
not ensure that real_dev is freed after macsec. That will trigger the<br />
UAF bug for real_dev as following:<br />
<br />
==================================================================<br />
BUG: KASAN: use-after-free in macsec_get_iflink+0x5f/0x70 drivers/net/macsec.c:3662<br />
Call Trace:<br />
...<br />
macsec_get_iflink+0x5f/0x70 drivers/net/macsec.c:3662<br />
dev_get_iflink+0x73/0xe0 net/core/dev.c:637<br />
default_operstate net/core/link_watch.c:42 [inline]<br />
rfc2863_policy+0x233/0x2d0 net/core/link_watch.c:54<br />
linkwatch_do_dev+0x2a/0x150 net/core/link_watch.c:161<br />
<br />
Allocated by task 22209:<br />
...<br />
alloc_netdev_mqs+0x98/0x1100 net/core/dev.c:10549<br />
rtnl_create_link+0x9d7/0xc00 net/core/rtnetlink.c:3235<br />
veth_newlink+0x20e/0xa90 drivers/net/veth.c:1748<br />
<br />
Freed by task 8:<br />
...<br />
kfree+0xd6/0x4d0 mm/slub.c:4552<br />
kvfree+0x42/0x50 mm/util.c:615<br />
device_release+0x9f/0x240 drivers/base/core.c:2229<br />
kobject_cleanup lib/kobject.c:673 [inline]<br />
kobject_release lib/kobject.c:704 [inline]<br />
kref_put include/linux/kref.h:65 [inline]<br />
kobject_put+0x1c8/0x540 lib/kobject.c:721<br />
netdev_run_todo+0x72e/0x10b0 net/core/dev.c:10327<br />
<br />
After commit faab39f63c1f ("net: allow out-of-order netdev unregistration")<br />
and commit e5f80fcf869a ("ipv6: give an IPv6 dev to blackhole_netdev"), we<br />
can add dev_hold_track() in macsec_dev_init() and dev_put_track() in<br />
macsec_free_netdev() to fix the problem.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.14.154 (including) | 4.15 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.19.84 (including) | 4.20 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.3.11 (including) | 5.17.15 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.18 (including) | 5.18.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page