-

CVE-2022-50504

In the Linux kernel, the following vulnerability has been resolved:

powerpc/rtas: avoid scheduling in rtas_os_term()

It's unsafe to use rtas_busy_delay() to handle a busy status from
the ibm,os-term RTAS function in rtas_os_term():

Kernel panic - not syncing: Attempted to kill init! exitcode=0x0000000b
BUG: sleeping function called from invalid context at arch/powerpc/kernel/rtas.c:618
in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 1, name: swapper/0
preempt_count: 2, expected: 0
CPU: 7 PID: 1 Comm: swapper/0 Tainted: G      D            6.0.0-rc5-02182-gf8553a572277-dirty #9
Call Trace:
[c000000007b8f000] [c000000001337110] dump_stack_lvl+0xb4/0x110 (unreliable)
[c000000007b8f040] [c0000000002440e4] __might_resched+0x394/0x3c0
[c000000007b8f0e0] [c00000000004f680] rtas_busy_delay+0x120/0x1b0
[c000000007b8f100] [c000000000052d04] rtas_os_term+0xb8/0xf4
[c000000007b8f180] [c0000000001150fc] pseries_panic+0x50/0x68
[c000000007b8f1f0] [c000000000036354] ppc_panic_platform_handler+0x34/0x50
[c000000007b8f210] [c0000000002303c4] notifier_call_chain+0xd4/0x1c0
[c000000007b8f2b0] [c0000000002306cc] atomic_notifier_call_chain+0xac/0x1c0
[c000000007b8f2f0] [c0000000001d62b8] panic+0x228/0x4d0
[c000000007b8f390] [c0000000001e573c] do_exit+0x140c/0x1420
[c000000007b8f480] [c0000000001e586c] make_task_dead+0xdc/0x200

Use rtas_busy_delay_time() instead, which signals without side effects
whether to attempt the ibm,os-term RTAS call again.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < f413135b337c4e90c1e593c6613f8717e17bc724
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 4768935b8cc2d2afeb7956292df0f6e2c49ca0a5
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < ffa991a003abb4f8cb9e5004646bfe2d9a46912c
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 515959eb49e6d218a46979d66f36fdef329ac7d2
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 6f7e2fcab73372a371ab4017cbedf7a71f4f9b40
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 7280fdb80bf0fe35d9b799fc7009f2cbe0a397d7
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < bed48651c87bef59ea1a9d6dbc381bcbc452f4ff
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 482d990a5dd1027ee0b70a8a570d56749cac8103
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 6c606e57eecc37d6b36d732b1ff7e55b7dc32dd4
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version <= 4.9.*
Version 4.9.337
Status unaffected
Version <= 4.14.*
Version 4.14.303
Status unaffected
Version <= 4.19.*
Version 4.19.270
Status unaffected
Version <= 5.4.*
Version 5.4.229
Status unaffected
Version <= 5.10.*
Version 5.10.163
Status unaffected
Version <= 5.15.*
Version 5.15.87
Status unaffected
Version <= 6.0.*
Version 6.0.17
Status unaffected
Version <= 6.1.*
Version 6.1.3
Status unaffected
Version <= *
Version 6.2
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.084
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string