CVE-2022-49537

Summary

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Fix call trace observed during I/O with CMF enabled

The following was seen with CMF enabled:

BUG: using smp_processor_id() in preemptible code: systemd-udevd/31711 kernel: caller is lpfc_update_cmf_cmd+0x214/0x420 [lpfc] kernel: CPU: 12 PID: 31711 Comm: systemd-udevd kernel: Call Trace: kernel: <TASK> kernel: dump_stack_lvl+0x44/0x57 kernel: check_preemption_disabled+0xbf/0xe0 kernel: lpfc_update_cmf_cmd+0x214/0x420 [lpfc] kernel: lpfc_nvme_fcp_io_submit+0x23b4/0x4df0 [lpfc]

this_cpu_ptr() calls smp_processor_id() in a preemptible context.

Fix by using per_cpu_ptr() with raw_smp_processor_id() instead.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux02243836ad6f384284f10302e6b820b893960d1c < ae373d66c427812754db5292eb1481b181daf9ceaffected
LinuxLinux02243836ad6f384284f10302e6b820b893960d1c < cd7f899de4b1b829125d72ee6fbfd878b637b815affected
LinuxLinux02243836ad6f384284f10302e6b820b893960d1c < 517e0835cfb2007713ff16c4fb8479f08b16aec7affected
LinuxLinux02243836ad6f384284f10302e6b820b893960d1c < d6d45f67a11136cb88a70a29ab22ea6db8ae6bd5affected
LinuxLinux5.15affected
LinuxLinux0 < 5.15unaffected
LinuxLinux5.15.46 <= 5.15.*unaffected
LinuxLinux5.17.14 <= 5.17.*unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

References