CVE-2022-48862

MEDIUM EPSS 10.9%
Published Jul 16, 20241y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 16, 2024 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: vhost: fix hung thread due to erroneous iotlb entries In vhost_iotlb_add_range_ctx(), range size can overflow to 0 when start is 0 and last is ULONG_MAX. One instance where it can happen is when userspace sends an IOTLB message with iova=size=uaddr=0 (vhost_process_iotlb_msg). So, an entry with size = 0, start = 0, last = ULONG_MAX ends up in the iotlb. Next time a packet is sent, iotlb_access_ok() loops indefinitely due to that erroneous entry. Call Trace: <TASK> iotlb_access_ok+0x21b/0x3e0 drivers/vhost/vhost.c:1340 vq_meta_prefetch+0xbc/0x280 drivers/vhost/vhost.c:1366 vhost_transport_do_send_pkt+0xe0/0xfd0 drivers/vhost/vsock.c:104 vhost_worker+0x23d/0x3d0 drivers/vhost/vhost.c:372 kthread+0x2e9/0x3a0 kernel/kthread.c:377 ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295 </TASK> Reported by syzbot at: https://syzkaller.appspot.com/bug?extid=0abd373e2e50d704db87 To fix this, do two things: 1. Return -EINVAL in vhost_chr_write_iter() when userspace asks to map a range with size 0. 2. Fix vhost_iotlb_add_range_ctx() to handle the range [0, ULONG_MAX] by splitting it into two entries.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
10.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-835

Affected Products 2

VendorProductVersionRange
linuxlinux_kernel*≥5.7  –  <5.15.29
linuxlinux_kernel*≥5.16  –  <5.16.15

References 3

  • git.kernel.org https://git.kernel.org/stable/c/d9a747e6b6561280bf1791bb24c5e9e082193dad
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e2ae38cf3d91837a493cb2093c87700ff3cbe667
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f8d88e86e90ea1002226d7ac2430152bfea003d1
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/d9a747e6b6561280bf1791bb24c5e9e082193dad
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e2ae38cf3d91837a493cb2093c87700ff3cbe667
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f8d88e86e90ea1002226d7ac2430152bfea003d1
    Patch