We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-49207

bpf, sockmap: Fix memleak in sk_psock_queue_msg



Description

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix memleak in sk_psock_queue_msg If tcp_bpf_sendmsg is running during a tear down operation we may enqueue data on the ingress msg queue while tear down is trying to free it. sk1 (redirect sk2) sk2 ------------------- --------------- tcp_bpf_sendmsg() tcp_bpf_send_verdict() tcp_bpf_sendmsg_redir() bpf_tcp_ingress() sock_map_close() lock_sock() lock_sock() ... blocking sk_psock_stop sk_psock_clear_state(psock, SK_PSOCK_TX_ENABLED); release_sock(sk); lock_sock() sk_mem_charge() get_page() sk_psock_queue_msg() sk_psock_test_state(psock, SK_PSOCK_TX_ENABLED); drop_sk_msg() release_sock() While drop_sk_msg(), the msg has charged memory form sk by sk_mem_charge and has sg pages need to put. To fix we use sk_msg_free() and then kfee() msg. This issue can cause the following info: WARNING: CPU: 0 PID: 9202 at net/core/stream.c:205 sk_stream_kill_queues+0xc8/0xe0 Call Trace: <IRQ> inet_csk_destroy_sock+0x55/0x110 tcp_rcv_state_process+0xe5f/0xe90 ? sk_filter_trim_cap+0x10d/0x230 ? tcp_v4_do_rcv+0x161/0x250 tcp_v4_do_rcv+0x161/0x250 tcp_v4_rcv+0xc3a/0xce0 ip_protocol_deliver_rcu+0x3d/0x230 ip_local_deliver_finish+0x54/0x60 ip_local_deliver+0xfd/0x110 ? ip_protocol_deliver_rcu+0x230/0x230 ip_rcv+0xd6/0x100 ? ip_local_deliver+0x110/0x110 __netif_receive_skb_one_core+0x85/0xa0 process_backlog+0xa4/0x160 __napi_poll+0x29/0x1b0 net_rx_action+0x287/0x300 __do_softirq+0xff/0x2fc do_softirq+0x79/0x90 </IRQ> WARNING: CPU: 0 PID: 531 at net/ipv4/af_inet.c:154 inet_sock_destruct+0x175/0x1b0 Call Trace: <TASK> __sk_destruct+0x24/0x1f0 sk_psock_destroy+0x19b/0x1c0 process_one_work+0x1b3/0x3c0 ? process_one_work+0x3c0/0x3c0 worker_thread+0x30/0x350 ? process_one_work+0x3c0/0x3c0 kthread+0xe6/0x110 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x22/0x30 </TASK>

Reserved 2025-02-26 | Published 2025-02-26 | Updated 2025-02-26 | Assigner Linux

Product status

Default status
unaffected

9635720b7c88592214562cb72605bdab6708006c before ef9785f429794567792561a584901faa9291d3ee
affected

9635720b7c88592214562cb72605bdab6708006c before 4dd2e947d3be13a4de3b3028859b9a6497266bcf
affected

9635720b7c88592214562cb72605bdab6708006c before 03948ed6553960db62f1c33bec29e64d7c191a3f
affected

9635720b7c88592214562cb72605bdab6708006c before 938d3480b92fa5e454b7734294f12a7b75126f09
affected

Default status
affected

5.14
affected

Any version before 5.14
unaffected

5.15.33
unaffected

5.16.19
unaffected

5.17.2
unaffected

5.18
unaffected

References

git.kernel.org/...c/ef9785f429794567792561a584901faa9291d3ee

git.kernel.org/...c/4dd2e947d3be13a4de3b3028859b9a6497266bcf

git.kernel.org/...c/03948ed6553960db62f1c33bec29e64d7c191a3f

git.kernel.org/...c/938d3480b92fa5e454b7734294f12a7b75126f09

cve.org (CVE-2022-49207)

nvd.nist.gov (CVE-2022-49207)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2022-49207

Support options

Helpdesk Chat, Email, Knowledgebase
MonTueWedThuFriSatSun
311234567891011121314151617181920212223242526272829301234567891011
MonTueWedThuFriSatSun
311234567891011121314151617181920212223242526272829301234567891011