From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4F65C1AB35C for ; Thu, 20 Jun 2024 11:17:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718882222; cv=none; b=nJDCWeuQRTqdyG7aRW14JGxtW5/6NYadGHhYP0MrNXER/6Dkae8Zpr4xl28F5uDXHq8cxwrfV0jOjLph49vBOWn7LnOpWX5ifDc1orQrHTXVbQCBWzz0Gq4iGEA2IuyU3N0ykWHRKo0bRIr28pMMa+0szzTAjz8PdUUdu5E43Tw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718882222; c=relaxed/simple; bh=1IhBJNNsgCbSu6P8DAR4/NwO1fTyRh6UlFjiAMr01vI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=uSgQxNhrmR3XqbZ3wnXPeZ4H9ZTOmkQk1lffLfxpNhodhtNvR09XQK5BEjNwJbWbYKZecTiO39OTgyD2kS73tYFcf72m8jdyAEbEU7PnI+zOUXXyugYDE3Gz+aqfA5LW9z98q5/XTZzFlbyajJ1+mfOnf808CE7z7lFztEmChvA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Q/MlqDSs; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Q/MlqDSs" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CC7E5C2BD10; Thu, 20 Jun 2024 11:17:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1718882222; bh=1IhBJNNsgCbSu6P8DAR4/NwO1fTyRh6UlFjiAMr01vI=; h=From:To:Cc:Subject:Date:Reply-to:From; b=Q/MlqDSsTrAiQb6YwReGN7zky8KqT0Gtanh0PmFMoM5/lfOOmk+pn6AsmsqjMX5t0 3M+kLc5ktC7wH51rfDnegT2IsUXY/Mut7ASxLQ17gi9HwaxF8Q9bNPaK27jbq7f8M8 236n+XT1IIucifgXCGE72Vs31XuQvD2EULFWUoYM= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2022-48735: ALSA: hda: Fix UAF of leds class devs at unbinding Date: Thu, 20 Jun 2024 13:16:15 +0200 Message-ID: <2024062001-CVE-2022-48735-32e6@gregkh> X-Mailer: git-send-email 2.45.2 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=2378; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=1IhBJNNsgCbSu6P8DAR4/NwO1fTyRh6UlFjiAMr01vI=; b=owGbwMvMwCRo6H6F97bub03G02pJDGkl/IW5ayc8rOF7/XLt/Wfls25s+7o6U+aqYvjtrCr1Q g/bKPUlHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCR/ACG+eF8Xb8OHFiyfOm/ 6BvTVmg4eXkk7WSYH5kSq2/WYtvq/sDHd+tK9fD9E1kbAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix UAF of leds class devs at unbinding The LED class devices that are created by HD-audio codec drivers are registered via devm_led_classdev_register() and associated with the HD-audio codec device. Unfortunately, it turned out that the devres release doesn't work for this case; namely, since the codec resource release happens before the devm call chain, it triggers a NULL dereference or a UAF for a stale set_brightness_delay callback. For fixing the bug, this patch changes the LED class device register and unregister in a manual manner without devres, keeping the instances in hda_gen_spec. The Linux kernel CVE team has assigned CVE-2022-48735 to this issue. Affected and fixed versions =========================== Fixed in 5.10.99 with commit a7de1002135c Fixed in 5.15.22 with commit 0e629052f013 Fixed in 5.16.8 with commit 813e9f3e06d2 Fixed in 5.17 with commit 549f8ffc7b2f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2022-48735 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: sound/pci/hda/hda_generic.c sound/pci/hda/hda_generic.h Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a7de1002135cf94367748ffc695a29812d7633b5 https://git.kernel.org/stable/c/0e629052f013eeb61494d4df2f1f647c2a9aef47 https://git.kernel.org/stable/c/813e9f3e06d22e29872d4fd51b54992d89cf66c8 https://git.kernel.org/stable/c/549f8ffc7b2f7561bea7f90930b6c5104318e87b