#VU93378 Race condition in Linux kernel - CVE-2022-48645
Published: June 26, 2024 / Updated: May 13, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a race condition within the enetc_vf_set_features() and enetc_vf_netdev_setup() functions in drivers/net/ethernet/freescale/enetc/enetc_vf.c, within the enetc_pf_set_features() function in drivers/net/ethernet/freescale/enetc/enetc_pf.c, within the enetc_close() and enetc_setup_tc_mqprio() functions in drivers/net/ethernet/freescale/enetc/enetc.c, within the fsl-enetc-$() function in drivers/net/ethernet/freescale/enetc/Makefile. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/510e703e4ed0e011db860bc21228aff48fc9eea7
- https://git.kernel.org/stable/c/23022b74b1a23bed044f6bc96cf92f6ca5f3e75f
- https://git.kernel.org/stable/c/5641c751fe2f92d3d9e8a8e03c1263ac8caa0b42
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.71
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0