{"id":"DEBIAN-CVE-2022-48811","details":"In the Linux kernel, the following vulnerability has been resolved:  ibmvnic: don't release napi in __ibmvnic_open()  If __ibmvnic_open() encounters an error such as when setting link state, it calls release_resources() which frees the napi structures needlessly. Instead, have __ibmvnic_open() only clean up the work it did so far (i.e. disable napi and irqs) and leave the rest to the callers.  If caller of __ibmvnic_open() is ibmvnic_open(), it should release the resources immediately. If the caller is do_reset() or do_hard_reset(), they will release the resources on the next reset.  This fixes following crash that occurred when running the drmgr command several times to add/remove a vnic interface:  \t[102056] ibmvnic 30000003 env3: Disabling rx_scrq[6] irq \t[102056] ibmvnic 30000003 env3: Disabling rx_scrq[7] irq \t[102056] ibmvnic 30000003 env3: Replenished 8 pools \tKernel attempted to read user page (10) - exploit attempt? (uid: 0) \tBUG: Kernel NULL pointer dereference on read at 0x00000010 \tFaulting instruction address: 0xc000000000a3c840 \tOops: Kernel access of bad area, sig: 11 [#1] \tLE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries \t... \tCPU: 9 PID: 102056 Comm: kworker/9:2 Kdump: loaded Not tainted 5.16.0-rc5-autotest-g6441998e2e37 #1 \tWorkqueue: events_long __ibmvnic_reset [ibmvnic] \tNIP:  c000000000a3c840 LR: c0080000029b5378 CTR: c000000000a3c820 \tREGS: c0000000548e37e0 TRAP: 0300   Not tainted  (5.16.0-rc5-autotest-g6441998e2e37) \tMSR:  8000000000009033 \u003cSF,EE,ME,IR,DR,RI,LE\u003e  CR: 28248484  XER: 00000004 \tCFAR: c0080000029bdd24 DAR: 0000000000000010 DSISR: 40000000 IRQMASK: 0 \tGPR00: c0080000029b55d0 c0000000548e3a80 c0000000028f0200 0000000000000000 \t... \tNIP [c000000000a3c840] napi_enable+0x20/0xc0 \tLR [c0080000029b5378] __ibmvnic_open+0xf0/0x430 [ibmvnic] \tCall Trace: \t[c0000000548e3a80] [0000000000000006] 0x6 (unreliable) \t[c0000000548e3ab0] [c0080000029b55d0] __ibmvnic_open+0x348/0x430 [ibmvnic] \t[c0000000548e3b40] [c0080000029bcc28] __ibmvnic_reset+0x500/0xdf0 [ibmvnic] \t[c0000000548e3c60] [c000000000176228] process_one_work+0x288/0x570 \t[c0000000548e3d00] [c000000000176588] worker_thread+0x78/0x660 \t[c0000000548e3da0] [c0000000001822f0] kthread+0x1c0/0x1d0 \t[c0000000548e3e10] [c00000000000cf64] ret_from_kernel_thread+0x5c/0x64 \tInstruction dump: \t7d2948f8 792307e0 4e800020 60000000 3c4c01eb 384239e0 f821ffd1 39430010 \t38a0fff6 e92d1100 f9210028 39200000 \u003ce9030010\u003e f9010020 60420000 e9210020 \t---[ end trace 5f8033b08fd27706 ]---","modified":"2026-09-01T16:04:35.726064670Z","published":"2024-07-16T12:15:05.367Z","upstream":["CVE-2022-48811"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-48811"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48811.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48811.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48811.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}