Wind River Support Network

HomeDefectsLIN1022-9452
Fixed

LIN1022-9452 : Security Advisory - linux - CVE-2022-48745

Created: Jun 20, 2024    Updated: Jun 25, 2024
Resolved Date: Jun 24, 2024
Found In Version: 10.22.33.1
Fix Version: 10.22.33.17
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: Use del_timer_sync in fw reset flow of halting poll

Substitute del_timer() with del_timer_sync() in fw reset polling
deactivation flow, in order to prevent a race condition which occurs
when del_timer() is called and timer is deactivated while another
process is handling the timer interrupt. A situation that led to
the following call trace:
        RIP: 0010:run_timer_softirq+0x137/0x420
        <IRQ>
        recalibrate_cpu_khz+0x10/0x10
        ktime_get+0x3e/0xa0
        ? sched_clock_cpu+0xb/0xc0
        __do_softirq+0xf5/0x2ea
        irq_exit_rcu+0xc1/0xf0
        sysvec_apic_timer_interrupt+0x9e/0xc0
        asm_sysvec_apic_timer_interrupt+0x12/0x20
        </IRQ>

CREATE(Triage):(User=admin) CVE-2022-48745 (https://nvd.nist.gov/vuln/detail/CVE-2022-48745)

CVEs


Live chat
Online