CVE-2022-49321
Published: Feb 26, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: treat all calls not a bcall when bc_serv is NULL When a rdma server returns a fault format reply, nfs v3 client may treats it as a bcall when bc service is not exist. The debug message at rpcrdma_bc_receive_call are, [56579.837169] RPC: rpcrdma_bc_receive_call: callback XID 00000001, length=20 [56579.837174] RPC: rpcrdma_bc_receive_call: 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 After that, rpcrdma_bc_receive_call will meets NULL pointer as, [ 226.057890] BUG: unable to handle kernel NULL pointer dereference at 00000000000000c8 ... [ 226.058704] RIP: 0010:_raw_spin_lock+0xc/0x20 ... [ 226.059732] Call Trace: [ 226.059878] rpcrdma_bc_receive_call+0x138/0x327 [rpcrdma] [ 226.060011] __ib_process_cq+0x89/0x170 [ib_core] [ 226.060092] ib_cq_poll_work+0x26/0x80 [ib_core] [ 226.060257] process_one_work+0x1a7/0x360 [ 226.060367] ? create_worker+0x1a0/0x1a0 [ 226.060440] worker_thread+0x30/0x390 [ 226.060500] ? create_worker+0x1a0/0x1a0 [ 226.060574] kthread+0x116/0x130 [ 226.060661] ? kthread_flush_work_fn+0x10/0x10 [ 226.060724] ret_from_fork+0x35/0x40 ...
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 63cae47005af51c937f4cdcc4835f29075add2ba - < 8e3943c50764dc7c5f25911970c3ff062ec1f18caffected 63cae47005af51c937f4cdcc4835f29075add2ba - < 998d35a2aff4b81a1c784f3aa45cd3afff6814c1affected 63cae47005af51c937f4cdcc4835f29075add2ba - < da99331fa62131a38a0947a8204c5208de7b0454affected 63cae47005af51c937f4cdcc4835f29075add2ba - < 8dbae5affbdbf524b48000f9d357925bb001e5f4affected 63cae47005af51c937f4cdcc4835f29075add2ba - < a3fc8051ee061e31db13e2fe011e8e0b71a7f815+3 more versions |
Linux | Linux | affected 4.4unaffected 0 - < 4.4unaffected 4.14.283 - <= 4.14.*unaffected 4.19.247 - <= 4.19.*unaffected 5.4.198 - <= 5.4.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now