{"id":"DEBIAN-CVE-2022-49441","details":"In the Linux kernel, the following vulnerability has been resolved:  tty: fix deadlock caused by calling printk() under tty_port-\u003elock  pty_write() invokes kmalloc() which may invoke a normal printk() to print failure message.  This can cause a deadlock in the scenario reported by syz-bot below:         CPU0              CPU1                    CPU2        ----              ----                    ----                          lock(console_owner);                                                  lock(&port_lock_key);   lock(&port-\u003elock);                          lock(&port_lock_key);                                                  lock(&port-\u003elock);   lock(console_owner);  As commit dbdda842fe96 (\"printk: Add console owner and waiter logic to load balance console writes\") said, such deadlock can be prevented by using printk_deferred() in kmalloc() (which is invoked in the section guarded by the port-\u003elock).  But there are too many printk() on the kmalloc() path, and kmalloc() can be called from anywhere, so changing printk() to printk_deferred() is too complicated and inelegant.  Therefore, this patch chooses to specify __GFP_NOWARN to kmalloc(), so that printk() will not be called, and this deadlock problem can be avoided.  Syzbot reported the following lockdep error:  ====================================================== WARNING: possible circular locking dependency detected 5.4.143-00237-g08ccc19a-dirty #10 Not tainted ------------------------------------------------------ syz-executor.4/29420 is trying to acquire lock: ffffffff8aedb2a0 (console_owner){....}-{0:0}, at: console_trylock_spinning kernel/printk/printk.c:1752 [inline] ffffffff8aedb2a0 (console_owner){....}-{0:0}, at: vprintk_emit+0x2ca/0x470 kernel/printk/printk.c:2023  but task is already holding lock: ffff8880119c9158 (&port-\u003elock){-.-.}-{2:2}, at: pty_write+0xf4/0x1f0 drivers/tty/pty.c:120  which lock already depends on the new lock.  the existing dependency chain (in reverse order) is:  -\u003e #2 (&port-\u003elock){-.-.}-{2:2}:        __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]        _raw_spin_lock_irqsave+0x35/0x50 kernel/locking/spinlock.c:159        tty_port_tty_get drivers/tty/tty_port.c:288 [inline]          \t\t\u003c-- lock(&port-\u003elock);        tty_port_default_wakeup+0x1d/0xb0 drivers/tty/tty_port.c:47        serial8250_tx_chars+0x530/0xa80 drivers/tty/serial/8250/8250_port.c:1767        serial8250_handle_irq.part.0+0x31f/0x3d0 drivers/tty/serial/8250/8250_port.c:1854        serial8250_handle_irq drivers/tty/serial/8250/8250_port.c:1827 [inline] \t\u003c-- lock(&port_lock_key);        serial8250_default_handle_irq+0xb2/0x220 drivers/tty/serial/8250/8250_port.c:1870        serial8250_interrupt+0xfd/0x200 drivers/tty/serial/8250/8250_core.c:126        __handle_irq_event_percpu+0x109/0xa50 kernel/irq/handle.c:156        [...]  -\u003e #1 (&port_lock_key){-.-.}-{2:2}:        __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]        _raw_spin_lock_irqsave+0x35/0x50 kernel/locking/spinlock.c:159        serial8250_console_write+0x184/0xa40 drivers/tty/serial/8250/8250_port.c:3198 \t\t\t\t\t\t\t\t\t\t\u003c-- lock(&port_lock_key);        call_console_drivers kernel/printk/printk.c:1819 [inline]        console_unlock+0x8cb/0xd00 kernel/printk/printk.c:2504        vprintk_emit+0x1b5/0x470 kernel/printk/printk.c:2024\t\t\t\u003c-- lock(console_owner);        vprintk_func+0x8d/0x250 kernel/printk/printk_safe.c:394        printk+0xba/0xed kernel/printk/printk.c:2084        register_console+0x8b3/0xc10 kernel/printk/printk.c:2829        univ8250_console_init+0x3a/0x46 drivers/tty/serial/8250/8250_core.c:681        console_init+0x49d/0x6d3 kernel/printk/printk.c:2915        start_kernel+0x5e9/0x879 init/main.c:713        secondary_startup_64+0xa4/0xb0 arch/x86/kernel/head_64.S:241  -\u003e #0 (console_owner){....}-{0:0}:        [...]        lock_acquire+0x127/0x340 kernel/locking/lockdep.c:4734        console_trylock_spinning kernel/printk/printk.c:1773  ---truncated---","modified":"2026-09-01T16:05:32.469756715Z","published":"2025-02-26T07:01:20.523Z","upstream":["CVE-2022-49441"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49441"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49441.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49441.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49441.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}