CVE-2022-48926
Published: Aug 22, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: add spinlock for rndis response list There's no lock for rndis response list. It could cause list corruption if there're two different list_add at the same time like below. It's better to add in rndis_add_response / rndis_free_response / rndis_get_next_response to prevent any race condition on response list. [ 361.894299] [1: irq/191-dwc3:16979] list_add corruption. next->prev should be prev (ffffff80651764d0), but was ffffff883dc36f80. (next=ffffff80651764d0). [ 361.904380] [1: irq/191-dwc3:16979] Call trace: [ 361.904391] [1: irq/191-dwc3:16979] __list_add_valid+0x74/0x90 [ 361.904401] [1: irq/191-dwc3:16979] rndis_msg_parser+0x168/0x8c0 [ 361.904409] [1: irq/191-dwc3:16979] rndis_command_complete+0x24/0x84 [ 361.904417] [1: irq/191-dwc3:16979] usb_gadget_giveback_request+0x20/0xe4 [ 361.904426] [1: irq/191-dwc3:16979] dwc3_gadget_giveback+0x44/0x60 [ 361.904434] [1: irq/191-dwc3:16979] dwc3_ep0_complete_data+0x1e8/0x3a0 [ 361.904442] [1: irq/191-dwc3:16979] dwc3_ep0_interrupt+0x29c/0x3dc [ 361.904450] [1: irq/191-dwc3:16979] dwc3_process_event_entry+0x78/0x6cc [ 361.904457] [1: irq/191-dwc3:16979] dwc3_process_event_buf+0xa0/0x1ec [ 361.904465] [1: irq/191-dwc3:16979] dwc3_thread_interrupt+0x34/0x5c
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected f6281af9d62e128aa6efad29cf7265062af114f2 - < 9f5d8ba538ef81cd86ea587ca3f8c77e26bea405affected f6281af9d62e128aa6efad29cf7265062af114f2 - < 669c2b178956718407af5631ccbc61c24413f038affected f6281af9d62e128aa6efad29cf7265062af114f2 - < 9f688aadede6b862a0a898792b1a35421c93636faffected f6281af9d62e128aa6efad29cf7265062af114f2 - < 9ab652d41deab49848673c3dadb57ad338485376affected f6281af9d62e128aa6efad29cf7265062af114f2 - < 4ce247af3f30078d5b97554f1ae6200a0222c15a+3 more versions |
Linux | Linux | affected 4.6unaffected 0 - < 4.6unaffected 4.9.304 - <= 4.9.*unaffected 4.14.269 - <= 4.14.*unaffected 4.19.232 - <= 4.19.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now