CVE-2022-48770

In the Linux kernel, the following vulnerability has been resolved: bpf: Guard against accessing NULL pt_regs in bpf_get_task_stack() task_pt_regs() can return NULL on powerpc for kernel threads. This is then used in __bpf_get_stack() to check for user mode, resulting in a kernel oops. Guard against this by checking return value of task_pt_regs() before trying to obtain the call chain.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*

History

06 Jan 2025, 21:43

Type Values Removed Values Added
CWE CWE-476
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/0bcd484587b3b3092e448d27dc369e347e1810c3 - () https://git.kernel.org/stable/c/0bcd484587b3b3092e448d27dc369e347e1810c3 - Patch
References () https://git.kernel.org/stable/c/b82ef4985a6d05e80f604624332430351df7b79a - () https://git.kernel.org/stable/c/b82ef4985a6d05e80f604624332430351df7b79a - Patch
References () https://git.kernel.org/stable/c/b992f01e66150fc5e90be4a96f5eb8e634c8249e - () https://git.kernel.org/stable/c/b992f01e66150fc5e90be4a96f5eb8e634c8249e - Patch
References () https://git.kernel.org/stable/c/ff6bdc205fd0a83bd365405d4e31fb5905826996 - () https://git.kernel.org/stable/c/ff6bdc205fd0a83bd365405d4e31fb5905826996 - Patch

21 Nov 2024, 07:33

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: bpf: protección contra el acceso a pt_regs NULL en bpf_get_task_stack() task_pt_regs() puede devolver NULL en powerpc para subprocesos del kernel. Luego, esto se usa en __bpf_get_stack() para verificar el modo de usuario, lo que genera un kernel ups. Protéjase contra esto verificando el valor de retorno de task_pt_regs() antes de intentar obtener la cadena de llamadas.
References () https://git.kernel.org/stable/c/0bcd484587b3b3092e448d27dc369e347e1810c3 - () https://git.kernel.org/stable/c/0bcd484587b3b3092e448d27dc369e347e1810c3 -
References () https://git.kernel.org/stable/c/b82ef4985a6d05e80f604624332430351df7b79a - () https://git.kernel.org/stable/c/b82ef4985a6d05e80f604624332430351df7b79a -
References () https://git.kernel.org/stable/c/b992f01e66150fc5e90be4a96f5eb8e634c8249e - () https://git.kernel.org/stable/c/b992f01e66150fc5e90be4a96f5eb8e634c8249e -
References () https://git.kernel.org/stable/c/ff6bdc205fd0a83bd365405d4e31fb5905826996 - () https://git.kernel.org/stable/c/ff6bdc205fd0a83bd365405d4e31fb5905826996 -

20 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-20 12:15

Updated : 2025-01-06 21:43


NVD link : CVE-2022-48770

Mitre link : CVE-2022-48770

CVE.ORG link : CVE-2022-48770


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference