CVE-2022-49636

Updated on 26 Feb 2025

Severity

5.5 Medium severity

Details

CVSS score
5.5
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

vlan: fix memory leak in vlan_newlink()

Blamed commit added back a bug I fixed in commit 9bbd917e0bec (“vlan: fix memory leak in vlan_dev_set_egress_priority”)

If a memory allocation fails in vlan_changelink() after other allocations succeeded, we need to call vlan_dev_free_egress_priority() to free all allocated memory because after a failed ->newlink() we do not call any methods like ndo_uninit() or dev->priv_destructor().

In following example, if the allocation for last element 2000:2001 fails, we need to free eight prior allocations:

ip link add link dummy0 dummy0.100 type vlan id 100
egress-qos-map 1:2 2:3 3:4 4:5 5:6 6:7 7:8 8:9 2000:2001

syzbot report was:

BUG: memory leak unreferenced object 0xffff888117bd1060 (size 32): comm “syz-executor408”, pid 3759, jiffies 4294956555 (age 34.090s) hex dump (first 32 bytes): 09 00 00 00 00 a0 00 00 00 00 00 00 00 00 00 00 ……………. 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ……………. backtrace: [<ffffffff83fc60ad>] kmalloc include/linux/slab.h:600 [inline] [<ffffffff83fc60ad>] vlan_dev_set_egress_priority+0xed/0x170 net/8021q/vlan_dev.c:193 [<ffffffff83fc6628>] vlan_changelink+0x178/0x1d0 net/8021q/vlan_netlink.c:128 [<ffffffff83fc67c8>] vlan_newlink+0x148/0x260 net/8021q/vlan_netlink.c:185 [<ffffffff838b1278>] rtnl_newlink_create net/core/rtnetlink.c:3363 [inline] [<ffffffff838b1278>] __rtnl_newlink+0xa58/0xdc0 net/core/rtnetlink.c:3580 [<ffffffff838b1629>] rtnl_newlink+0x49/0x70 net/core/rtnetlink.c:3593 [<ffffffff838ac66c>] rtnetlink_rcv_msg+0x21c/0x5c0 net/core/rtnetlink.c:6089 [<ffffffff839f9c37>] netlink_rcv_skb+0x87/0x1d0 net/netlink/af_netlink.c:2501 [<ffffffff839f8da7>] netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline] [<ffffffff839f8da7>] netlink_unicast+0x397/0x4c0 net/netlink/af_netlink.c:1345 [<ffffffff839f9266>] netlink_sendmsg+0x396/0x710 net/netlink/af_netlink.c:1921 [<ffffffff8384dbf6>] sock_sendmsg_nosec net/socket.c:714 [inline] [<ffffffff8384dbf6>] sock_sendmsg+0x56/0x80 net/socket.c:734 [<ffffffff8384e15c>] ____sys_sendmsg+0x36c/0x390 net/socket.c:2488 [<ffffffff838523cb>] ___sys_sendmsg+0x8b/0xd0 net/socket.c:2542 [<ffffffff838525b8>] __sys_sendmsg net/socket.c:2571 [inline] [<ffffffff838525b8>] __do_sys_sendmsg net/socket.c:2580 [inline] [<ffffffff838525b8>] __se_sys_sendmsg net/socket.c:2578 [inline] [<ffffffff838525b8>] __x64_sys_sendmsg+0x78/0xf0 net/socket.c:2578 [<ffffffff845ad8d5>] do_syscall_x64 arch/x86/entry/common.c:50 [inline] [<ffffffff845ad8d5>] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80 [<ffffffff8460006a>] entry_SYSCALL_64_after_hwframe+0x46/0xb0

Details

Affected packages:
kernel-uek @ 5.4.17 (+7 more)

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Proxmox VE 7 5.15 Released
5 kernels
  • 5.15.143-1-pve-5.15.143-1
  • 5.15.149-1-pve-5.15.149-1
  • 5.15.152-1-pve-5.15.152-1
  • 5.15.158-1-pve_5.15.158-1
  • 5.15.158-2-pve_5.15.158-2
Ubuntu 18.04 AWS Focal Will Not Fix
Ubuntu 20.04 Released
1 kernel
  • 5.4.0-216.236
Ubuntu 20.04 AWS Released
1 kernel
  • 5.4.0-1146.156
Ubuntu 20.04 Azure Released
1 kernel
  • 5.4.0-1151.158
Ubuntu 20.04 HWE AWS Released
23 kernels
  • 5.15.0-1056.61~20.04.1
  • 5.15.0-1057.63~20.04.1
  • 5.15.0-1058.64~20.04.1
  • 5.15.0-1061.67~20.04.1
  • 5.15.0-1062.68~20.04.1
  • 5.15.0-1063.69~20.04.1
  • 5.15.0-1064.70~20.04.1
  • 5.15.0-1065.71~20.04.1
  • 5.15.0-1066.72~20.04.1
  • 5.15.0-1067.73~20.04.1
  • 5.15.0-1068.74~20.04.1
  • 5.15.0-1069.75~20.04.1
  • 5.15.0-1070.76~20.04.1
  • 5.15.0-1071.77~20.04.1
  • 5.15.0-1072.78~20.04.1
  • 5.15.0-1073.79~20.04.1
  • 5.15.0-1075.82~20.04.1
  • 5.15.0-1077.84~20.04.1
  • 5.15.0-1080.87~20.04.1
  • 5.15.0-1081.88~20.04.1
  • 5.15.0-1082.89~20.04.1
  • 5.15.0-1083.90~20.04.1
  • 5.15.0-1084.91~20.04.1
Ubuntu 20.04 HWE Azure Released
23 kernels
  • 5.15.0-1058.66~20.04.2
  • 5.15.0-1059.67~20.04.1
  • 5.15.0-1060.69~20.04.1
  • 5.15.0-1061.70~20.04.1
  • 5.15.0-1063.72~20.04.1
  • 5.15.0-1064.73~20.04.1
  • 5.15.0-1067.76~20.04.1
  • 5.15.0-1068.77~20.04.1
  • 5.15.0-1065.74~20.04.1
  • 5.15.0-1070.79~20.04.1
  • 5.15.0-1071.80~20.04.1
  • 5.15.0-1072.81~20.04.1
  • 5.15.0-1073.82~20.04.1
  • 5.15.0-1074.83~20.04.1
  • 5.15.0-1075.84~20.04.1
  • 5.15.0-1078.87~20.04.1
  • 5.15.0-1079.88~20.04.1
  • 5.15.0-1081.90~20.04.1
  • 5.15.0-1082.91~20.04.1
  • 5.15.0-1086.95~20.04.1
  • 5.15.0-1087.96~20.04.1
  • 5.15.0-1088.97~20.04.1
  • 5.15.0-1089.98~20.04.1
Ubuntu 22.04 Released
29 kernels
  • 5.15.0-100.110
  • 5.15.0-101.111
  • 5.15.0-102.112
  • 5.15.0-105.115
  • 5.15.0-106.116
  • 5.15.0-107.117
  • 5.15.0-112.122
  • 5.15.0-113.123
  • 5.15.0-116.126
  • 5.15.0-117.127
  • 5.15.0-118.128
  • 5.15.0-119.129
  • 5.15.0-121.131
  • 5.15.0-122.132
  • 5.15.0-124.134
  • 5.15.0-125.135
  • 5.15.0-127.137
  • 5.15.0-130.140
  • 5.15.0-126.136
  • 5.15.0-131.141
  • 5.15.0-128.138
  • 5.15.0-133.144
  • 5.15.0-134.145
  • 5.15.0-135.146
  • 5.15.0-136.147
  • 5.15.0-138.148
  • 5.15.0-139.149
  • 5.15.0-140.150
  • 5.15.0-141.151
Ubuntu 22.04 AWS Released
25 kernels
  • 5.15.0-1056.61
  • 5.15.0-1057.63
  • 5.15.0-1060.66
  • 5.15.0-1061.67
  • 5.15.0-1062.68
  • 5.15.0-1063.69
  • 5.15.0-1064.70
  • 5.15.0-1065.71
  • 5.15.0-1066.72
  • 5.15.0-1067.73
  • 5.15.0-1068.74
  • 5.15.0-1069.75
  • 5.15.0-1070.76
  • 5.15.0-1071.77
  • 5.15.0-1072.78
  • 5.15.0-1073.79
  • 5.15.0-1076.83
  • 5.15.0-1078.85
  • 5.15.0-1079.86
  • 5.15.0-1080.87
  • 5.15.0-1081.88
  • 5.15.0-1082.89
  • 5.15.0-1083.90
  • 5.15.0-1084.91
  • 5.15.0-1085.92
Ubuntu 22.04 Azure Released
25 kernels
  • 5.15.0-1058.66
  • 5.15.0-1059.67
  • 5.15.0-1060.69
  • 5.15.0-1061.70
  • 5.15.0-1063.72
  • 5.15.0-1064.73
  • 5.15.0-1066.75
  • 5.15.0-1067.76
  • 5.15.0-1068.77
  • 5.15.0-1070.79
  • 5.15.0-1071.80
  • 5.15.0-1072.81
  • 5.15.0-1073.82
  • 5.15.0-1074.83
  • 5.15.0-1075.84
  • 5.15.0-1078.87
  • 5.15.0-1079.88
  • 5.15.0-1081.90
  • 5.15.0-1082.91
  • 5.15.0-1084.93
  • 5.15.0-1086.95
  • 5.15.0-1087.96
  • 5.15.0-1088.97
  • 5.15.0-1089.98
  • 5.15.0-1090.99