PT-2024-10522 · Linux+3 · Linux Kernel+3

Syzbot

·

Published

2022-02-08

·

Updated

2025-01-20

·

CVE-2022-48810

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.16.0
Description The vulnerability is related to the ipmr and ip6mr components of the Linux kernel, which are responsible for multicast routing. The issue arises from the failure to acquire the RTNL lock before calling the ip[6]mr free table() function on the failure path, leading to a potential denial-of-service condition. The RTNL lock is a mechanism used to protect the network namespace from concurrent modifications. When this lock is not acquired, it can result in unpredictable behavior, including crashes or freezes. The vulnerability can be exploited by an attacker to cause a denial-of-service condition, potentially disrupting network services.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, versions 5.16.0 and later should include the necessary patches to address this issue. Ensure that all affected systems are updated to prevent potential exploitation. If updating is not immediately possible, consider implementing additional monitoring and security measures to detect and respond to potential attacks exploiting this vulnerability.

Exploit

Fix

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01073
CVE-2022-48810
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse