CVE-2022-49311
Published: Feb 26, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8192bs: Fix deadlock in rtw_joinbss_event_prehandle() There is a deadlock in rtw_joinbss_event_prehandle(), which is shown below: (Thread 1) | (Thread 2) | _set_timer() rtw_joinbss_event_prehandle()| mod_timer() spin_lock_bh() //(1) | (wait a time) ... | _rtw_join_timeout_handler() del_timer_sync() | spin_lock_bh() //(2) (wait timer to stop) | ... We hold pmlmepriv->lock in position (1) of thread 1 and use del_timer_sync() to wait timer to stop, but timer handler also need pmlmepriv->lock in position (2) of thread 2. As a result, rtw_joinbss_event_prehandle() will block forever. This patch extracts del_timer_sync() from the protection of spin_lock_bh(), which could let timer handler to obtain the needed lock. What`s more, we change spin_lock_bh() to spin_lock_irq() in _rtw_join_timeout_handler() in order to prevent deadlock.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 554c0a3abf216c991c5ebddcdb2c08689ecd290b - < ae60744d5fad840b9d056d35b4b652d95e755846affected 554c0a3abf216c991c5ebddcdb2c08689ecd290b - < 1f6c99b94ca3caad346876b3e22e3ca3d25bc8eeaffected 554c0a3abf216c991c5ebddcdb2c08689ecd290b - < eca9748d9267a38d532464e3305a38629e9c35a9affected 554c0a3abf216c991c5ebddcdb2c08689ecd290b - < 041879b12ddb0c6c83ed9c0bdd10dc82a056f2fc |
Linux | Linux | affected 4.12unaffected 0 - < 4.12unaffected 5.15.47 - <= 5.15.*unaffected 5.17.15 - <= 5.17.*unaffected 5.18.4 - <= 5.18.*+1 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now