CVE-2022-48819

MEDIUM

Linux Kernel 5.16-5.16.9 - Denial of Service via Mixed splice() and sendmsg(MSG_ZEROCOPY)

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: tcp: take care of mixed splice()/sendmsg(MSG_ZEROCOPY) case syzbot found that mixing sendpage() and sendmsg(MSG_ZEROCOPY) calls over the same TCP socket would again trigger the infamous warning in inet_sock_destruct() WARN_ON(sk_forward_alloc_get(sk)); While Talal took into account a mix of regular copied data and MSG_ZEROCOPY one in the same skb, the sendpage() path has been forgotten. We want the charging to happen for sendpage(), because pages could be coming from a pipe. What is missing is the downgrading of pure zerocopy status to make sure sk_forward_alloc will stay synced. Add tcp_downgrade_zcopy_pure() helper so that we can use it from the two callers.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (9)
linux/Kernel 5.16.0 - 5.16.10linux
Linux/Linux < 5.16
Linux/Linux 5.16
Linux/Linux 5.16.10 - 5.16.*
Linux/Linux 5.17
Linux/Linux 9b65b17db72313b7a4fe9bc9502928c88be57986 - 47f3860c4931175f112f28dcac66eacca9b1040f
Linux/Linux 9b65b17db72313b7a4fe9bc9502928c88be57986 - f8d9d938514f46c4892aff6bfe32f425e84d81cc
linux/linux_kernel 5.17 rc1 (3 CPE variants)
linux/linux_kernel 5.16 - 5.16.10
Published Jul 16, 2024
Tracked Since Feb 18, 2026