PT-2024-11785 · Linux+2 · Linux Kernel+2
Published
2022-02-01
·
Updated
2025-01-13
·
CVE-2022-48719
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved, related to the neighbor entry turning to NUD FAILED state, where
neigh event send() triggered an immediate probe as per commit cd28ca0a3dd1 ("neigh: reduce arp latency") via neigh probe() given table lock was held. This situation can lead to a deadlock for NTF MANAGED entries. The fix adds a parameter to neigh event send() to communicate whether immediate probe is allowed or disallowed. Existing call-sites of neigh event send() default as-is to immediate probe, but neigh managed work() disables it via use of neigh event send probe().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os