{"id":"DEBIAN-CVE-2022-48818","details":"In the Linux kernel, the following vulnerability has been resolved:  net: dsa: mv88e6xxx: don't use devres for mdiobus  As explained in commits: 74b6d7d13307 (\"net: dsa: realtek: register the MDIO bus under devres\") 5135e96a3dd2 (\"net: dsa: don't allocate the slave_mii_bus using devres\")  mdiobus_free() will panic when called from devm_mdiobus_free() \u003c- devres_release_all() \u003c- __device_release_driver(), and that mdiobus was not previously unregistered.  The mv88e6xxx is an MDIO device, so the initial set of constraints that I thought would cause this (I2C or SPI buses which call -\u003eremove on -\u003eshutdown) do not apply. But there is one more which applies here.  If the DSA master itself is on a bus that calls -\u003eremove from -\u003eshutdown (like dpaa2-eth, which is on the fsl-mc bus), there is a device link between the switch and the DSA master, and device_links_unbind_consumers() will unbind the Marvell switch driver on shutdown.  systemd-shutdown[1]: Powering off. mv88e6085 0x0000000008b96000:00 sw_gl0: Link is Down fsl-mc dpbp.9: Removing from iommu group 7 fsl-mc dpbp.8: Removing from iommu group 7 ------------[ cut here ]------------ kernel BUG at drivers/net/phy/mdio_bus.c:677! Internal error: Oops - BUG: 0 [#1] PREEMPT SMP Modules linked in: CPU: 0 PID: 1 Comm: systemd-shutdow Not tainted 5.16.5-00040-gdc05f73788e5 #15 pc : mdiobus_free+0x44/0x50 lr : devm_mdiobus_free+0x10/0x20 Call trace:  mdiobus_free+0x44/0x50  devm_mdiobus_free+0x10/0x20  devres_release_all+0xa0/0x100  __device_release_driver+0x190/0x220  device_release_driver_internal+0xac/0xb0  device_links_unbind_consumers+0xd4/0x100  __device_release_driver+0x4c/0x220  device_release_driver_internal+0xac/0xb0  device_links_unbind_consumers+0xd4/0x100  __device_release_driver+0x94/0x220  device_release_driver+0x28/0x40  bus_remove_device+0x118/0x124  device_del+0x174/0x420  fsl_mc_device_remove+0x24/0x40  __fsl_mc_device_remove+0xc/0x20  device_for_each_child+0x58/0xa0  dprc_remove+0x90/0xb0  fsl_mc_driver_remove+0x20/0x5c  __device_release_driver+0x21c/0x220  device_release_driver+0x28/0x40  bus_remove_device+0x118/0x124  device_del+0x174/0x420  fsl_mc_bus_remove+0x80/0x100  fsl_mc_bus_shutdown+0xc/0x1c  platform_shutdown+0x20/0x30  device_shutdown+0x154/0x330  kernel_power_off+0x34/0x6c  __do_sys_reboot+0x15c/0x250  __arm64_sys_reboot+0x20/0x30  invoke_syscall.constprop.0+0x4c/0xe0  do_el0_svc+0x4c/0x150  el0_svc+0x24/0xb0  el0t_64_sync_handler+0xa8/0xb0  el0t_64_sync+0x178/0x17c  So the same treatment must be applied to all DSA switch drivers, which is: either use devres for both the mdiobus allocation and registration, or don't use devres at all.  The Marvell driver already has a good structure for mdiobus removal, so just plug in mdiobus_free and get rid of devres.","modified":"2026-09-01T16:05:29.401459732Z","published":"2024-07-16T12:15:05.813Z","upstream":["CVE-2022-48818"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-48818"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48818.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48818.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48818.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}