news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2022-48816

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
7.8 High
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Risk score
62.4
Published
2024-07-16
Status
Published

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: lock against ->sock changing during sysfs read ->sock can be set to NULL asynchronously unless ->recv_mutex is held. So it is important to hold that mutex. Otherwise a sysfs read can trigger an oops. Commit 17f09d3f619a ("SUNRPC: Check if the xprt is connected before handling sysfs reads") appears to attempt to fix this problem, but it only narrows the race window.

Coverage 2

Advisories and references