In the Linux kernel, the following vulnerability has been resolved:
vdpa: fix use-after-free on vpvdparemove
When vpvdpa driver is unbind, vpvdpa is freed in vdpaunregisterdevice and then vpvdpa->mdev.pcidev is dereferenced in vpmodernremove, triggering use-after-free.
Call Trace of unbinding driver free vpvdpa : dosyscall64 vfswrite kernfsfopwriteiter devicereleasedriverinternal pcideviceremove vpvdparemove vdpaunregisterdevice kobjectrelease devicerelease kfree
Call Trace of dereference vpvdpa->mdev.pcidev: vpmodernremove pcireleaseselectedregions pcireleaseregion pciresourcelen pciresource_end (dev)->resource[(bar)].end
[
{
"id": "CVE-2022-48861-32b72355",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dc54ba9932aeaaa1a21fe214af1f446593a78274",
"signature_type": "Line",
"target": {
"file": "drivers/vdpa/virtio_pci/vp_vdpa.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"67939581547542993416238223111444228771",
"9455220160242727722504191275243170211",
"171370134330914669926709641650838733067",
"150275178351174167824974942950148596494",
"309471375077810109868857174209292176433"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2022-48861-dea0d50a",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dc54ba9932aeaaa1a21fe214af1f446593a78274",
"signature_type": "Function",
"target": {
"file": "drivers/vdpa/virtio_pci/vp_vdpa.c",
"function": "vp_vdpa_remove"
},
"deprecated": false,
"digest": {
"length": 136.0,
"function_hash": "241382775225962557775050847701965236774"
},
"signature_version": "v1"
}
]