CVE-2022-48713
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
20/06/2024
Last modified:
17/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
perf/x86/intel/pt: Fix crash with stop filters in single-range mode<br />
<br />
Add a check for !buf->single before calling pt_buffer_region_size in a<br />
place where a missing check can cause a kernel crash.<br />
<br />
Fixes a bug introduced by commit 670638477aed ("perf/x86/intel/pt:<br />
Opportunistically use single range output mode"), which added a<br />
support for PT single-range output mode. Since that commit if a PT<br />
stop filter range is hit while tracing, the kernel will crash because<br />
of a null pointer dereference in pt_handle_status due to calling<br />
pt_buffer_region_size without a ToPA configured.<br />
<br />
The commit which introduced single-range mode guarded almost all uses of<br />
the ToPA buffer variables with checks of the buf->single variable, but<br />
missed the case where tracing was stopped by the PT hardware, which<br />
happens when execution hits a configured stop filter.<br />
<br />
Tested that hitting a stop filter while PT recording successfully<br />
records a trace with this patch but crashes without this patch.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.99 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.22 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.16.8 (excluding) |
| cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1d9093457b243061a9bba23543c38726e864a643
- https://git.kernel.org/stable/c/456f041e035913fcedb275aff6f8a71dfebcd394
- https://git.kernel.org/stable/c/e83d941fd3445f660d2f43647c580a320cc384f6
- https://git.kernel.org/stable/c/feffb6ae2c80b9a8206450cdef90f5943baced99
- https://git.kernel.org/stable/c/1d9093457b243061a9bba23543c38726e864a643
- https://git.kernel.org/stable/c/456f041e035913fcedb275aff6f8a71dfebcd394
- https://git.kernel.org/stable/c/e83d941fd3445f660d2f43647c580a320cc384f6
- https://git.kernel.org/stable/c/feffb6ae2c80b9a8206450cdef90f5943baced99



