Bug 1227964 (CVE-2022-48824) - VUL-0: CVE-2022-48824: kernel: scsi: myrs: fix crash in error case
Summary: VUL-0: CVE-2022-48824: kernel: scsi: myrs: fix crash in error case
Status: RESOLVED FIXED
Alias: CVE-2022-48824
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/414194/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-48824:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-16 16:32 UTC by SMASH SMASH
Modified: 2024-07-19 17:47 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-07-16 16:32:40 UTC
In the Linux kernel, the following vulnerability has been resolved:

scsi: myrs: Fix crash in error case

In myrs_detect(), cs->disable_intr is NULL when privdata->hw_init() fails
with non-zero. In this case, myrs_cleanup(cs) will call a NULL ptr and
crash the kernel.

[    1.105606] myrs 0000:00:03.0: Unknown Initialization Error 5A
[    1.105872] myrs 0000:00:03.0: Failed to initialize Controller
[    1.106082] BUG: kernel NULL pointer dereference, address: 0000000000000000
[    1.110774] Call Trace:
[    1.110950]  myrs_cleanup+0xe4/0x150 [myrs]
[    1.111135]  myrs_probe.cold+0x91/0x56a [myrs]
[    1.111302]  ? DAC960_GEM_intr_handler+0x1f0/0x1f0 [myrs]
[    1.111500]  local_pci_probe+0x48/0x90

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-48824
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2022/CVE-2022-48824.mbox
https://git.kernel.org/stable/c/5c5ceea00c8c9df150708e66cb9f2891192c1162
https://git.kernel.org/stable/c/0e42c4a3d732517edc3766dd45a14e60d29dd929
https://git.kernel.org/stable/c/6207f35c213f6cb2fc3f13b5e77f08c710e1de19
https://git.kernel.org/stable/c/1d6cd26605b4d662063a83c15c776b5299a1cb23
https://git.kernel.org/stable/c/4db09593af0b0b4d7d4805ebb3273df51d7cc30d
https://www.cve.org/CVERecord?id=CVE-2022-48824
Comment 1 Miroslav Franc 2024-07-19 16:56:54 UTC
Fixes: 77266186397c6