In the Linux kernel, the following vulnerability has been resolved:
mac802154: fix missing INITLISTHEAD in ieee802154ifadd()
Kernel fault injection test reports null-ptr-deref as follows:
BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:cfg802154netdevnotifiercall+0x120/0x310 include/linux/list.h:114 Call Trace: <TASK> rawnotifiercallchain+0x6d/0xa0 kernel/notifier.c:87 callnetdevicenotifiersinfo+0x6e/0xc0 net/core/dev.c:1944 unregisternetdevicemanynotify+0x60d/0xcb0 net/core/dev.c:1982 unregisternetdevicequeue+0x154/0x1a0 net/core/dev.c:10879 registernetdevice+0x9a8/0xb90 net/core/dev.c:10083 ieee802154ifadd+0x6ed/0x7e0 net/mac802154/iface.c:659 ieee802154registerhw+0x29c/0x330 net/mac802154/main.c:229 mcr20aprobe+0xaaa/0xcb1 drivers/net/ieee802154/mcr20a.c:1316
ieee802154ifadd() allocates wpandev as netdev's private data, but not init the list in struct wpandev. cfg802154netdevnotifier_call() manage the list when device register/unregister, and may lead to null-ptr-deref.
Use INITLISTHEAD() on it to initialize it correctly.
{ "vanir_signatures": [ { "target": { "file": "net/mac802154/iface.c", "function": "ieee802154_if_add" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7410f4d1221bb182510b7778ab6eefa8b9b7102d", "digest": { "length": 1511.0, "function_hash": "138045196473915297019045847973944693737" }, "id": "CVE-2022-48972-076db8af", "deprecated": false, "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9980a3ea20de40c83817877106c909cb032692d2", "digest": { "threshold": 0.9, "line_hashes": [ "32774217104211983525369166303862244955", "44744112480164598661271555878185382357", "17562472497132165710294917148455221791", "45737297952849172053008651277717376637" ] }, "id": "CVE-2022-48972-0d661fd1", "deprecated": false, "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b3d72d3135d2ef68296c1ee174436efd65386f04", "digest": { "threshold": 0.9, "line_hashes": [ "32774217104211983525369166303862244955", "44744112480164598661271555878185382357", "17562472497132165710294917148455221791", "45737297952849172053008651277717376637" ] }, "id": "CVE-2022-48972-11bbd376", "deprecated": false, "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7410f4d1221bb182510b7778ab6eefa8b9b7102d", "digest": { "threshold": 0.9, "line_hashes": [ "32774217104211983525369166303862244955", "44744112480164598661271555878185382357", "17562472497132165710294917148455221791", "45737297952849172053008651277717376637" ] }, "id": "CVE-2022-48972-252ec4c5", "deprecated": false, "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c", "function": "ieee802154_if_add" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9980a3ea20de40c83817877106c909cb032692d2", "digest": { "length": 1511.0, "function_hash": "138045196473915297019045847973944693737" }, "id": "CVE-2022-48972-2e28557e", "deprecated": false, "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c", "function": "ieee802154_if_add" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b3d72d3135d2ef68296c1ee174436efd65386f04", "digest": { "length": 1523.0, "function_hash": "297608381821441514434897916975459904620" }, "id": "CVE-2022-48972-33407a75", "deprecated": false, "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c", "function": "ieee802154_if_add" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1831d4540406708e48239cf38fd9c3b7ea98e08f", "digest": { "length": 1511.0, "function_hash": "138045196473915297019045847973944693737" }, "id": "CVE-2022-48972-75d33fe8", "deprecated": false, "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c", "function": "ieee802154_if_add" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a110287ef4a423980309490df632e1c1e73b3dc9", "digest": { "length": 1500.0, "function_hash": "293712722532061601412659322083322779133" }, "id": "CVE-2022-48972-a6c38412", "deprecated": false, "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f00c84fb1635c27ba24ec5df65d5bd7d7dc00008", "digest": { "threshold": 0.9, "line_hashes": [ "32774217104211983525369166303862244955", "44744112480164598661271555878185382357", "17562472497132165710294917148455221791", "45737297952849172053008651277717376637" ] }, "id": "CVE-2022-48972-b880f188", "deprecated": false, "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c", "function": "ieee802154_if_add" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f00c84fb1635c27ba24ec5df65d5bd7d7dc00008", "digest": { "length": 1511.0, "function_hash": "138045196473915297019045847973944693737" }, "id": "CVE-2022-48972-bd8917a9", "deprecated": false, "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@623918f40fa68e3bb21312a3fafb90f491bf5358", "digest": { "threshold": 0.9, "line_hashes": [ "32774217104211983525369166303862244955", "44744112480164598661271555878185382357", "17562472497132165710294917148455221791", "45737297952849172053008651277717376637" ] }, "id": "CVE-2022-48972-c4be56bb", "deprecated": false, "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a110287ef4a423980309490df632e1c1e73b3dc9", "digest": { "threshold": 0.9, "line_hashes": [ "32774217104211983525369166303862244955", "44744112480164598661271555878185382357", "17562472497132165710294917148455221791", "45737297952849172053008651277717376637" ] }, "id": "CVE-2022-48972-c666ef38", "deprecated": false, "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c", "function": "ieee802154_if_add" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@623918f40fa68e3bb21312a3fafb90f491bf5358", "digest": { "length": 1523.0, "function_hash": "297608381821441514434897916975459904620" }, "id": "CVE-2022-48972-ce4e3a58", "deprecated": false, "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1831d4540406708e48239cf38fd9c3b7ea98e08f", "digest": { "threshold": 0.9, "line_hashes": [ "32774217104211983525369166303862244955", "44744112480164598661271555878185382357", "17562472497132165710294917148455221791", "45737297952849172053008651277717376637" ] }, "id": "CVE-2022-48972-d6673356", "deprecated": false, "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@42c319635c0cf7eb36eccac6cda76532f47b61a3", "digest": { "threshold": 0.9, "line_hashes": [ "32774217104211983525369166303862244955", "44744112480164598661271555878185382357", "17562472497132165710294917148455221791", "45737297952849172053008651277717376637" ] }, "id": "CVE-2022-48972-ea769133", "deprecated": false, "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "net/mac802154/iface.c", "function": "ieee802154_if_add" }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@42c319635c0cf7eb36eccac6cda76532f47b61a3", "digest": { "length": 1511.0, "function_hash": "138045196473915297019045847973944693737" }, "id": "CVE-2022-48972-f13584b5", "deprecated": false, "signature_type": "Function", "signature_version": "v1" } ] }