CVE-2022-48816 (GCVE-0-2022-48816)
Vulnerability from cvelistv5
Published
2024-07-16 11:44
Modified
2026-08-05 08:52
Summary
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: lock against ->sock changing during sysfs read ->sock can be set to NULL asynchronously unless ->recv_mutex is held. So it is important to hold that mutex. Otherwise a sysfs read can trigger an oops. Commit 17f09d3f619a ("SUNRPC: Check if the xprt is connected before handling sysfs reads") appears to attempt to fix this problem, but it only narrows the race window.
Impacted products
Vendor Product Version
Linux Linux Version: a8482488a7d6d320f63a9ee1912dbb5ae5b80a61
Version: a8482488a7d6d320f63a9ee1912dbb5ae5b80a61
Version: a8482488a7d6d320f63a9ee1912dbb5ae5b80a61
Version: 21a2be1a5145d072deedc7cdc5b2d17380abea75
Version: 77876473912d1bf1ed16bffa1674e5ff0f499f25
Version: 5.10.67   
Version: 5.13.19   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T15:25:01.591Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/9482ab4540f5bcc869b44c067ae99b5fca16bd07"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/b49ea673e119f59c71645e2f65b3ccad857c90ee"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-48816",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T16:58:15.719556Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:00.382Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/sunrpc/sysfs.c",
            "net/sunrpc/xprtsock.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "fdc42287ae3f8a35cc2098307f52d7864b4bc8ed",
              "status": "affected",
              "version": "a8482488a7d6d320f63a9ee1912dbb5ae5b80a61",
              "versionType": "git"
            },
            {
              "lessThan": "9482ab4540f5bcc869b44c067ae99b5fca16bd07",
              "status": "affected",
              "version": "a8482488a7d6d320f63a9ee1912dbb5ae5b80a61",
              "versionType": "git"
            },
            {
              "lessThan": "b49ea673e119f59c71645e2f65b3ccad857c90ee",
              "status": "affected",
              "version": "a8482488a7d6d320f63a9ee1912dbb5ae5b80a61",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "21a2be1a5145d072deedc7cdc5b2d17380abea75",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "77876473912d1bf1ed16bffa1674e5ff0f499f25",
              "versionType": "git"
            },
            {
              "lessThan": "5.11",
              "status": "affected",
              "version": "5.10.67",
              "versionType": "semver"
            },
            {
              "lessThan": "5.14",
              "status": "affected",
              "version": "5.13.19",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/sunrpc/sysfs.c",
            "net/sunrpc/xprtsock.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.14"
            },
            {
              "lessThan": "5.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.16.*",
              "status": "unaffected",
              "version": "5.16.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "5.17",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.209",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.16.10",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.17",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.10.67",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.13.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: lock against -\u003esock changing during sysfs read\n\n-\u003esock can be set to NULL asynchronously unless -\u003erecv_mutex is held.\nSo it is important to hold that mutex.  Otherwise a sysfs read can\ntrigger an oops.\nCommit 17f09d3f619a (\"SUNRPC: Check if the xprt is connected before\nhandling sysfs reads\") appears to attempt to fix this problem, but it\nonly narrows the race window."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable path is reached only by reading world-readable SUNRPC sysfs attributes under /sys/kernel/sunrpc/xprt-switches/*/xprt-*/{srcaddr,xprt_info}, which requires local process access and is not reachable via network packets or adjacent-link protocols.\nAC:L - An unprivileged attacker can continuously poll those attributes while inducing concurrent transport teardown (NFS automount idle unmount, peer RST/reconnect storms, or forced disconnect), controlling both sides of the race and retrying until sock is observed NULL or freed mid-getsockname.\nPR:L - srcaddr is mode 0644 and xprt_info is 0444 with no capability check on the show path, and /sys/kernel/sunrpc directories are world-traversable, so a normal local user can trigger the vulnerable reads without root or init-namespace privileges.\nUI:N - The attacker performs the sysfs reads and can drive teardown/reconnect themselves; no separate victim action such as opening a crafted file or mounting a filesystem is required at exploit time.\nS:U - Impact is confined to the local host kernel (oops or socket UAF within SUNRPC/socket heap state) and does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - Without recv_mutex, a non-NULL sock pointer can be loaded then used after xs_reset_transport()\u0027s fput frees the socket, a classic socket UAF that heap spraying can turn into arbitrary kernel memory disclosure.\nI:H - The same unlocked race allows use-after-free of the struct socket while kernel_getsockname/xs_sock_getport runs, enabling reclaim and corruption of adjacent heap state for arbitrary write and control-flow hijacking under standard UAF exploitation.\nA:H - The documented failure mode is a kernel oops from NULL sock dereference during sysfs read, and the UAF path likewise crashes on stale socket use, so availability impact is High even without a full exploit."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:52:28.866Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fdc42287ae3f8a35cc2098307f52d7864b4bc8ed"
        },
        {
          "url": "https://git.kernel.org/stable/c/9482ab4540f5bcc869b44c067ae99b5fca16bd07"
        },
        {
          "url": "https://git.kernel.org/stable/c/b49ea673e119f59c71645e2f65b3ccad857c90ee"
        }
      ],
      "title": "SUNRPC: lock against -\u003esock changing during sysfs read",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-48816",
    "datePublished": "2024-07-16T11:44:04.654Z",
    "dateReserved": "2024-07-16T11:38:08.900Z",
    "dateUpdated": "2026-08-05T08:52:28.866Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/9482ab4540f5bcc869b44c067ae99b5fca16bd07\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/b49ea673e119f59c71645e2f65b3ccad857c90ee\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-03T15:25:01.591Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2022-48816\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T16:58:15.719556Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:14.016Z\"}}], \"cna\": {\"title\": \"SUNRPC: lock against -\u003esock changing during sysfs read\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerable path is reached only by reading world-readable SUNRPC sysfs attributes under /sys/kernel/sunrpc/xprt-switches/*/xprt-*/{srcaddr,xprt_info}, which requires local process access and is not reachable via network packets or adjacent-link protocols.\\nAC:L - An unprivileged attacker can continuously poll those attributes while inducing concurrent transport teardown (NFS automount idle unmount, peer RST/reconnect storms, or forced disconnect), controlling both sides of the race and retrying until sock is observed NULL or freed mid-getsockname.\\nPR:L - srcaddr is mode 0644 and xprt_info is 0444 with no capability check on the show path, and /sys/kernel/sunrpc directories are world-traversable, so a normal local user can trigger the vulnerable reads without root or init-namespace privileges.\\nUI:N - The attacker performs the sysfs reads and can drive teardown/reconnect themselves; no separate victim action such as opening a crafted file or mounting a filesystem is required at exploit time.\\nS:U - Impact is confined to the local host kernel (oops or socket UAF within SUNRPC/socket heap state) and does not cross a VM, IOMMU, or other security-authority boundary.\\nC:H - Without recv_mutex, a non-NULL sock pointer can be loaded then used after xs_reset_transport()\u0027s fput frees the socket, a classic socket UAF that heap spraying can turn into arbitrary kernel memory disclosure.\\nI:H - The same unlocked race allows use-after-free of the struct socket while kernel_getsockname/xs_sock_getport runs, enabling reclaim and corruption of adjacent heap state for arbitrary write and control-flow hijacking under standard UAF exploitation.\\nA:H - The documented failure mode is a kernel oops from NULL sock dereference during sysfs read, and the UAF path likewise crashes on stale socket use, so availability impact is High even without a full exploit.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"a8482488a7d6d320f63a9ee1912dbb5ae5b80a61\", \"lessThan\": \"fdc42287ae3f8a35cc2098307f52d7864b4bc8ed\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a8482488a7d6d320f63a9ee1912dbb5ae5b80a61\", \"lessThan\": \"9482ab4540f5bcc869b44c067ae99b5fca16bd07\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a8482488a7d6d320f63a9ee1912dbb5ae5b80a61\", \"lessThan\": \"b49ea673e119f59c71645e2f65b3ccad857c90ee\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"21a2be1a5145d072deedc7cdc5b2d17380abea75\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"77876473912d1bf1ed16bffa1674e5ff0f499f25\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5.10.67\", \"lessThan\": \"5.11\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.13.19\", \"lessThan\": \"5.14\", \"versionType\": \"semver\"}], \"programFiles\": [\"net/sunrpc/sysfs.c\", \"net/sunrpc/xprtsock.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.14\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.14\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.209\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"5.16.10\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.16.*\"}, {\"status\": \"unaffected\", \"version\": \"5.17\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/sunrpc/sysfs.c\", \"net/sunrpc/xprtsock.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/fdc42287ae3f8a35cc2098307f52d7864b4bc8ed\"}, {\"url\": \"https://git.kernel.org/stable/c/9482ab4540f5bcc869b44c067ae99b5fca16bd07\"}, {\"url\": \"https://git.kernel.org/stable/c/b49ea673e119f59c71645e2f65b3ccad857c90ee\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nSUNRPC: lock against -\u003esock changing during sysfs read\\n\\n-\u003esock can be set to NULL asynchronously unless -\u003erecv_mutex is held.\\nSo it is important to hold that mutex.  Otherwise a sysfs read can\\ntrigger an oops.\\nCommit 17f09d3f619a (\\\"SUNRPC: Check if the xprt is connected before\\nhandling sysfs reads\\\") appears to attempt to fix this problem, but it\\nonly narrows the race window.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.209\", \"versionStartIncluding\": \"5.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.16.10\", \"versionStartIncluding\": \"5.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.17\", \"versionStartIncluding\": \"5.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"5.10.67\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"5.13.19\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T08:52:28.866Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2022-48816\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T08:52:28.866Z\", \"dateReserved\": \"2024-07-16T11:38:08.900Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-07-16T11:44:04.654Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…