In the Linux kernel, the following vulnerability has been resolved:
vdpa: fix use-after-free on vpvdparemove
When vpvdpa driver is unbind, vpvdpa is freed in vdpaunregisterdevice and then vpvdpa->mdev.pcidev is dereferenced in vpmodernremove, triggering use-after-free.
Call Trace of unbinding driver free vpvdpa : dosyscall64 vfswrite kernfsfopwriteiter devicereleasedriverinternal pcideviceremove vpvdparemove vdpaunregisterdevice kobjectrelease devicerelease kfree
Call Trace of dereference vpvdpa->mdev.pcidev: vpmodernremove pcireleaseselectedregions pcireleaseregion pciresourcelen pciresource_end (dev)->resource[(bar)].end
[ { "signature_type": "Line", "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dc54ba9932aeaaa1a21fe214af1f446593a78274", "signature_version": "v1", "target": { "file": "drivers/vdpa/virtio_pci/vp_vdpa.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "67939581547542993416238223111444228771", "9455220160242727722504191275243170211", "171370134330914669926709641650838733067", "150275178351174167824974942950148596494", "309471375077810109868857174209292176433" ] }, "id": "CVE-2022-48861-32b72355" }, { "signature_type": "Function", "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dc54ba9932aeaaa1a21fe214af1f446593a78274", "signature_version": "v1", "target": { "function": "vp_vdpa_remove", "file": "drivers/vdpa/virtio_pci/vp_vdpa.c" }, "digest": { "function_hash": "241382775225962557775050847701965236774", "length": 136.0 }, "id": "CVE-2022-48861-dea0d50a" } ]