CVE-2022-49379
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2025
Last modified:
22/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
driver core: Fix wait_for_device_probe() & deferred_probe_timeout interaction<br />
<br />
Mounting NFS rootfs was timing out when deferred_probe_timeout was<br />
non-zero [1]. This was because ip_auto_config() initcall times out<br />
waiting for the network interfaces to show up when<br />
deferred_probe_timeout was non-zero. While ip_auto_config() calls<br />
wait_for_device_probe() to make sure any currently running deferred<br />
probe work or asynchronous probe finishes, that wasn&#39;t sufficient to<br />
account for devices being deferred until deferred_probe_timeout.<br />
<br />
Commit 35a672363ab3 ("driver core: Ensure wait_for_device_probe() waits<br />
until the deferred_probe_timeout fires") tried to fix that by making<br />
sure wait_for_device_probe() waits for deferred_probe_timeout to expire<br />
before returning.<br />
<br />
However, if wait_for_device_probe() is called from the kernel_init()<br />
context:<br />
<br />
- Before deferred_probe_initcall() [2], it causes the boot process to<br />
hang due to a deadlock.<br />
<br />
- After deferred_probe_initcall() [3], it blocks kernel_init() from<br />
continuing till deferred_probe_timeout expires and beats the point of<br />
deferred_probe_timeout that&#39;s trying to wait for userspace to load<br />
modules.<br />
<br />
Neither of this is good. So revert the changes to<br />
wait_for_device_probe().<br />
<br />
[1] - https://lore.kernel.org/lkml/TYAPR01MB45443DF63B9EF29054F7C41FD8C60@TYAPR01MB4544.jpnprd01.prod.outlook.com/<br />
[2] - https://lore.kernel.org/lkml/YowHNo4sBjr9ijZr@dev-arch.thelio-3990X/<br />
[3] - https://lore.kernel.org/lkml/Yo3WvGnNk3LvLb7R@linutronix.de/
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.7.1 (including) | 5.10.122 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.47 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.17.15 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.18 (including) | 5.18.4 (excluding) |
| cpe:2.3:o:linux:linux_kernel:5.7:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.7:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.7:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.7:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/29357883a89193863f3cc6a2c5e0b42ceb022761
- https://git.kernel.org/stable/c/4ad6af07efcca85369c21e4897b3020cff2c170b
- https://git.kernel.org/stable/c/528229474e1cbb1b3451cb713d94aecb5f6ee264
- https://git.kernel.org/stable/c/5ee76c256e928455212ab759c51d198fedbe7523
- https://git.kernel.org/stable/c/71cbce75031aed26c72c2dc8a83111d181685f1b



