{"id":"DEBIAN-CVE-2022-48721","details":"In the Linux kernel, the following vulnerability has been resolved:  net/smc: Forward wakeup to smc socket waitqueue after fallback  When we replace TCP with SMC and a fallback occurs, there may be some socket waitqueue entries remaining in smc socket-\u003ewq, such as eppoll_entries inserted by userspace applications.  After the fallback, data flows over TCP/IP and only clcsocket-\u003ewq will be woken up. Applications can't be notified by the entries which were inserted in smc socket-\u003ewq before fallback. So we need a mechanism to wake up smc socket-\u003ewq at the same time if some entries remaining in it.  The current workaround is to transfer the entries from smc socket-\u003ewq to clcsock-\u003ewq during the fallback. But this may cause a crash like this:   general protection fault, probably for non-canonical address 0xdead000000000100: 0000 [#1] PREEMPT SMP PTI  CPU: 3 PID: 0 Comm: swapper/3 Kdump: loaded Tainted: G E     5.16.0+ #107  RIP: 0010:__wake_up_common+0x65/0x170  Call Trace:   \u003cIRQ\u003e   __wake_up_common_lock+0x7a/0xc0   sock_def_readable+0x3c/0x70   tcp_data_queue+0x4a7/0xc40   tcp_rcv_established+0x32f/0x660   ? sk_filter_trim_cap+0xcb/0x2e0   tcp_v4_do_rcv+0x10b/0x260   tcp_v4_rcv+0xd2a/0xde0   ip_protocol_deliver_rcu+0x3b/0x1d0   ip_local_deliver_finish+0x54/0x60   ip_local_deliver+0x6a/0x110   ? tcp_v4_early_demux+0xa2/0x140   ? tcp_v4_early_demux+0x10d/0x140   ip_sublist_rcv_finish+0x49/0x60   ip_sublist_rcv+0x19d/0x230   ip_list_rcv+0x13e/0x170   __netif_receive_skb_list_core+0x1c2/0x240   netif_receive_skb_list_internal+0x1e6/0x320   napi_complete_done+0x11d/0x190   mlx5e_napi_poll+0x163/0x6b0 [mlx5_core]   __napi_poll+0x3c/0x1b0   net_rx_action+0x27c/0x300   __do_softirq+0x114/0x2d2   irq_exit_rcu+0xb4/0xe0   common_interrupt+0xba/0xe0   \u003c/IRQ\u003e   \u003cTASK\u003e  The crash is caused by privately transferring waitqueue entries from smc socket-\u003ewq to clcsock-\u003ewq. The owners of these entries, such as epoll, have no idea that the entries have been transferred to a different socket wait queue and still use original waitqueue spinlock (smc socket-\u003ewq.wait.lock) to make the entries operation exclusive, but it doesn't work. The operations to the entries, such as removing from the waitqueue (now is clcsock-\u003ewq after fallback), may cause a crash when clcsock waitqueue is being iterated over at the moment.  This patch tries to fix this by no longer transferring wait queue entries privately, but introducing own implementations of clcsock's callback functions in fallback situation. The callback functions will forward the wakeup to smc socket-\u003ewq if clcsock-\u003ewq is actually woken up and smc socket-\u003ewq has remaining entries.","modified":"2026-09-01T16:05:28.872557203Z","published":"2024-06-20T11:15:55.620Z","upstream":["CVE-2022-48721"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-48721"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48721.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48721.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48721.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}