SB2024082231 - Improper locking in Linux kernel ulp srp driver
Published: August 22, 2024 Updated: May 12, 2025
Security Bulletin ID
SB2024082231
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-48930)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the srp_remove_one() function in drivers/infiniband/ulp/srp/ib_srp.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/8cc342508f9e7fdccd2e9758ae9d52aff72dab7f
- https://git.kernel.org/stable/c/4752fafb461821f8c8581090c923ababba68c5bd
- https://git.kernel.org/stable/c/d7997d19dfa7001ca41e971cd9efd091bb195b51
- https://git.kernel.org/stable/c/901206f71e6ad2b2e7accefc5199a438d173c25f
- https://git.kernel.org/stable/c/99eb8d694174c777558dc902d575d1997d5ca650
- https://git.kernel.org/stable/c/c8b56e51aa91b8e7df3a98388dce3fdabd15c1d4
- https://git.kernel.org/stable/c/98d056603ce55ceb90631b3927151c190dfb1b27
- https://git.kernel.org/stable/c/081bdc9fe05bb23248f5effb6f811da3da4b8252
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.269
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.232
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.304
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.103
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.26
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.182