CVE-2022-50475

Description

A NULL pointer dereference flaw was found in the Linux kernel RDMA core's sysfs handling. A local user with access to InfiniBand sysfs nodes can read sysfs attributes while an InfiniBand port is being removed, causing the kernel to dereference a NULL ib_port pointer when the port structure has been freed but sysfs access is still possible, which results in a NULL pointer dereference and denial of service through kernel crash.

Déclaration

The issue arises because sysfs attribute handlers fail to validate that the ib_port pointer is non-NULL before dereferencing it. When userspace accesses sysfs nodes under /sys/class/infiniband/ (such as port state, capabilities, or statistics), the kernel retrieves the associated port structure. During device removal or port state changes, the port structure can be freed while sysfs nodes still exist. If a sysfs read occurs during or after this removal, the code dereferences a NULL or freed ib_port pointer, causing a kernel crash. This can be triggered by simply reading sysfs attributes while removing or reconfiguring InfiniBand devices.

Détails du score du système commun d'évaluation des vulnérabilités (CVSS)

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

Répartition des scores CVSS v3

Red HatNVDcve.org
Score de base5.55.5N/A
Vecteur d'attaqueLocalLocalN/A
Complexité de l'attaqueLowLowN/A
Privilèges requisLowLowN/A
Interaction avec l'utilisateurNoneNoneN/A
Champ d'applicationUnchangedUnchangedN/A
ConfidentialitéNoneNoneN/A
Impact sur l'intégritéNoneNoneN/A
Impact sur la disponibilitéHighHighN/A

Vecteur

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Comprendre la Défaillance (CWE)

Confidentiality

Technical Impact: Read Memory

If the expired pointer is used in a read operation, an attacker might be able to control data read in by the application.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

If the expired pointer references a memory location that is not accessible to the product, or points to a location that is "malformed" (such as NULL) or larger than expected by a read or write operation, then a crash may occur.

Integrity,Confidentiality,Availability

Technical Impact: Execute Unauthorized Code or Commands

If the expired pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.

Questions fréquemment posées

Vous souhaitez recevoir des notifications d'errata ? Signez ici.