PT-2022-7702 · Linux+2 · Linux Kernel+2

Published

2022-12-07

·

Updated

2026-05-26

·

CVE-2022-48887

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the simultaneous execution of commands using a shared resource with incorrect synchronization in the Linux kernel's drm/vmwgfx component. This can lead to a crash when command buffers are submitted from two different threads. The problem is fixed by replacing the buggy rcu paths with a regular spin lock, which resolves the races in accesses to shared resources and fixes kernel crashes seen in the IGT's vmwgfx execution buffer stress test and with apps using shared resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Weakness Enumeration

Related Identifiers

AZL-48771
BDU:2025-00783
CVE-2022-48887
OESA-2024-2123
OESA-2024-2125
OESA-2024-2126
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3483-1

Affected Products

Debian
Linux Kernel
Suse