PT-2023-9439 · Linux+1 · Linux Kernel+1

Michael Walle

·

Published

2023-01-13

·

Updated

2024-09-24

·

CVE-2022-48895

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.0-rc5-00088-gf3600ff8e322 #1930
Description The vulnerability is related to the iommu/arm-smmu component in the Linux kernel. It occurs when the system is shut down with the "reboot -f" command while a packet transmission is in flight, causing a kernel NULL pointer dereference. This can lead to a kernel panic and a fatal exception in interrupt. The issue is reproducible when the board has a fixed IP address and is ping flooded from another host.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the iommu/arm-smmu vulnerability. Alternatively, boot with the "arm-smmu.disable bypass=0" option to allow unknown Stream IDs, but this may have security implications.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-07590
CVE-2022-48895

Affected Products

Linux Kernel
Red Os