CVE-2022-48780

MEDIUM

Linux Kernel 5.15.22-5.15.24 and 5.16.8-5.16.10 - Infinite Loop via SMC Fallback Callback Overwrite

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net/smc: Avoid overwriting the copies of clcsock callback functions The callback functions of clcsock will be saved and replaced during the fallback. But if the fallback happens more than once, then the copies of these callback functions will be overwritten incorrectly, resulting in a loop call issue: clcsk->sk_error_report |- smc_fback_error_report() <------------------------------| |- smc_fback_forward_wakeup() | (loop) |- clcsock_callback() (incorrectly overwritten) | |- smc->clcsk_error_report() ------------------| So this patch fixes the issue by saving these function pointers only once in the fallback and avoiding overwriting.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 13.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (9)
linux/Kernel 5.15.22 - 5.15.25linux
linux/Kernel 5.16.8 - 5.16.11linux
Linux/Linux 0ef6049f664941bc0f75828b3a61877635048b27 - 7de7ba7a8bd4fde0141de8674c13514d0072f0e6
Linux/Linux 341adeec9adad0874f29a0a1af35638207352a39 - 1de9770d121ee9294794cca0e0be8fbfa0134ee8
Linux/Linux 5.15.22 - 5.15.25
Linux/Linux 5.16.8 - 5.16.11
Linux/Linux 504078fbe9dd570d685361b57784a6050bc40aaa - f00b6c976ae0dfbd9b891175f713f59095d23842
linux/linux_kernel 5.17 rc3 (2 CPE variants)
linux/linux_kernel 5.15.22 - 5.15.25
Published Jul 16, 2024
Tracked Since Feb 18, 2026