CVE-2022-48819
MEDIUMLinux Kernel 5.16-5.16.9 - Denial of Service via Mixed splice() and sendmsg(MSG_ZEROCOPY)
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: tcp: take care of mixed splice()/sendmsg(MSG_ZEROCOPY) case syzbot found that mixing sendpage() and sendmsg(MSG_ZEROCOPY) calls over the same TCP socket would again trigger the infamous warning in inet_sock_destruct() WARN_ON(sk_forward_alloc_get(sk)); While Talal took into account a mix of regular copied data and MSG_ZEROCOPY one in the same skb, the sendpage() path has been forgotten. We want the charging to happen for sendpage(), because pages could be coming from a pipe. What is missing is the downgrading of pure zerocopy status to make sure sk_forward_alloc will stay synced. Add tcp_downgrade_zcopy_pure() helper so that we can use it from the two callers.
References (2)
Core 2
Scores
CVSS v3
5.5
EPSS
0.0023
EPSS Percentile
13.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (9)
linux/Kernel
5.16.0 - 5.16.10linux
Linux/Linux
< 5.16
Linux/Linux
5.16
Linux/Linux
5.16.10 - 5.16.*
Linux/Linux
5.17
Linux/Linux
9b65b17db72313b7a4fe9bc9502928c88be57986 - 47f3860c4931175f112f28dcac66eacca9b1040f
Linux/Linux
9b65b17db72313b7a4fe9bc9502928c88be57986 - f8d9d938514f46c4892aff6bfe32f425e84d81cc
linux/linux_kernel
5.17 rc1 (3 CPE variants)
linux/linux_kernel
5.16 - 5.16.10
Published
Jul 16, 2024
Tracked Since
Feb 18, 2026