CVE-2022-49304

Summary

In the Linux kernel, the following vulnerability has been resolved:

drivers: tty: serial: Fix deadlock in sa1100_set_termios()

There is a deadlock in sa1100_set_termios(), which is shown below:

(Thread 1) | (Thread 2) | sa1100_enable_ms() sa1100_set_termios() | mod_timer() spin_lock_irqsave() //(1) | (wait a time) … | sa1100_timeout() del_timer_sync() | spin_lock_irqsave() //(2) (wait timer to stop) | …

We hold sport->port.lock in position (1) of thread 1 and use del_timer_sync() to wait timer to stop, but timer handler also need sport->port.lock in position (2) of thread 2. As a result, sa1100_set_termios() will block forever.

This patch moves del_timer_sync() before spin_lock_irqsave() in order to prevent the deadlock.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0976808d0d171ec837d4bd3e9f4ad4a00ab703b8affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 85e20f8bd31a46d8c60103d0274a8ebe8f47f2b2affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 920f0ae7a129ffee98a106e3bbdfd61a2a59e939affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 09a5958a2452ad22d0cb638711ef34ea1863a829affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6e2273eefab54a521d9c59efb6e1114e742bdf41affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2cbfc38df580bff5b2fe19f21c1a7520efcc4b3baffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 553213432ef0c295becdc08c0207d2094468f673affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 34d91e555e5582cffdbcbb75517bc9217866823eaffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 62b2caef400c1738b6d22f636c628d9f85cd4c4caffected
LinuxLinux2.6.12affected
LinuxLinux0 < 2.6.12unaffected
LinuxLinux4.9.318 <= 4.9.*unaffected
LinuxLinux4.14.283 <= 4.14.*unaffected
LinuxLinux4.19.247 <= 4.19.*unaffected
LinuxLinux5.4.198 <= 5.4.*unaffected
LinuxLinux5.10.122 <= 5.10.*unaffected
LinuxLinux5.15.47 <= 5.15.*unaffected
LinuxLinux5.17.15 <= 5.17.*unaffected
LinuxLinux5.18.4 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References