CVE-2022-50498
Description
A missing synchronization flaw was found in the Linux kernel's Atheros alx Ethernet driver in the suspend/resume path. A local user can trigger this issue during system suspend/resume operations when the driver fails to acquire the rtnl_lock mutex before calling internal network device open functions. This causes an RTNL assertion failure, resulting in a kernel warning or potential race conditions during device state transitions.
Statement
The alx driver performs device close and reopen operations during suspend/resume without holding the required rtnl_lock mutex. The network core expects this lock to be held when changing device queue configuration, and trips an assertion when it detects the lock is missing. While the driver implements its own internal locking and doesn't actually change queue counts, the missing rtnl_lock violates kernel locking conventions and could potentially lead to races if the network core state changes during suspend/resume.
Mitigation
To mitigate this issue, prevent the alx module from being loaded. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 3.3 | 5.5 | N/A |
| Attack Vector | Local | Local | N/A |
| Attack Complexity | Low | Low | N/A |
| Privileges Required | Low | Low | N/A |
| User Interaction | None | None | N/A |
| Scope | Unchanged | Unchanged | N/A |
| Confidentiality | None | None | N/A |
| Integrity Impact | None | None | N/A |
| Availability Impact | Low | High | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Integrity,Availability
Technical Impact: Modify Application Data; DoS: Instability; DoS: Crash, Exit, or Restart
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.