CVE-2022-50498

MEDIUM

Linux Kernel 5.14-5.14, 5.16-5.19.17, 5.20-6.0.3 - Denial of Service via RTNL Assertion Failure in alx Resume

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: eth: alx: take rtnl_lock on resume Zbynek reports that alx trips an rtnl assertion on resume: RTNL: assertion failed at net/core/dev.c (2891) RIP: 0010:netif_set_real_num_tx_queues+0x1ac/0x1c0 Call Trace: <TASK> __alx_open+0x230/0x570 [alx] alx_resume+0x54/0x80 [alx] ? pci_legacy_resume+0x80/0x80 dpm_run_callback+0x4a/0x150 device_resume+0x8b/0x190 async_resume+0x19/0x30 async_run_entry_fn+0x30/0x130 process_one_work+0x1e5/0x3b0 indeed the driver does not hold rtnl_lock during its internal close and re-open functions during suspend/resume. Note that this is not a huge bug as the driver implements its own locking, and does not implement changing the number of queues, but we need to silence the splat.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (14)
linux/Kernel 5.14.0 - 5.15.75linux
linux/Kernel 5.16.0 - 5.19.17linux
linux/Kernel 5.20.0 - 6.0.3linux
Linux/Linux < 5.14
Linux/Linux 4a5fe57e775188be96359a1934501be45fe5f705 - 6ad1c94e1e7e374d88f0cfd77936dddb8339aaba
Linux/Linux 4a5fe57e775188be96359a1934501be45fe5f705 - 6f1991a940b90753b34570f093a21dba366e8cc0
Linux/Linux 4a5fe57e775188be96359a1934501be45fe5f705 - a845a0c4bdece2c0073ecea2fca7c4d5f0550f78
Linux/Linux 4a5fe57e775188be96359a1934501be45fe5f705 - c0323c0fd07804d5874699e93f935cda0d989c67
Linux/Linux 5.14
Linux/Linux 5.15.75 - 5.15.*
... and 4 more
Published Oct 04, 2025
Tracked Since Feb 18, 2026