CVE-2022-50498

Description

A missing synchronization flaw was found in the Linux kernel's Atheros alx Ethernet driver in the suspend/resume path. A local user can trigger this issue during system suspend/resume operations when the driver fails to acquire the rtnl_lock mutex before calling internal network device open functions. This causes an RTNL assertion failure, resulting in a kernel warning or potential race conditions during device state transitions.

Statement

The alx driver performs device close and reopen operations during suspend/resume without holding the required rtnl_lock mutex. The network core expects this lock to be held when changing device queue configuration, and trips an assertion when it detects the lock is missing. While the driver implements its own internal locking and doesn't actually change queue counts, the missing rtnl_lock violates kernel locking conventions and could potentially lead to races if the network core state changes during suspend/resume.

Mitigation

To mitigate this issue, prevent the alx module from being loaded. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score3.35.5N/A
Attack VectorLocalLocalN/A
Attack ComplexityLowLowN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactLowHighN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Integrity,Availability

Technical Impact: Modify Application Data; DoS: Instability; DoS: Crash, Exit, or Restart

Frequently Asked Questions

Want to get errata notifications? Sign up here.