Wind River Support Network

HomeDefectsLIN1021-4486
Fixed

LIN1021-4486 : Security Advisory - linux - CVE-2022-41848

Created: Oct 8, 2022    Updated: Sep 8, 2025
Resolved Date: Aug 10, 2025
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioctl and mgslpc_detach.

This fix of CVE has not been accepted by upstream for many years. From the patch comments this bug is only occurred when user physically removes the PCMCIA device while calling ioctl() for this tty device node so this is a race for rare hardware that is unlikely to be in use in 2025.
Live chat
Online