From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C887321767B for ; Wed, 26 Feb 2025 02:14:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740536099; cv=none; b=V1uZaYytxfMRoazkGYnTz4Ybbrt8hPi61Qi48eB8qi45GeZ6wvSe7TvExWsatKMHcL+VM0B81Fi4L5dejGuP+8DP5ZSJXrhoPeVAkAQdio1kZMnyD2o4y4mbGrW1SBCYJ8O6KXp02/2tJSjBFFWYW5r9GVzAc1S9o1zOcYTRoEA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740536099; c=relaxed/simple; bh=8zAFLRHLBImssd3aYrvLb7ISxNPa1CLxbzmk34T3zHA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=CuJ5yNYYxEkmI3kKv3oVWVY1hssG/JSKM7LB9NAFBF1dTxV1S1pK6JazS/1vUGD8ogiZEByXE/XyjPWRWp6la1MQhE4FaHOljPA39LnEIE6VPQyUCIs8x5s+QLifRFhb63JyNJNJkCcrltrbqhGoRVPIGv0B6Q0XLU+AlOqnfq4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=UDLg0Bw4; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="UDLg0Bw4" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9BC71C4CEDD; Wed, 26 Feb 2025 02:14:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1740536099; bh=8zAFLRHLBImssd3aYrvLb7ISxNPa1CLxbzmk34T3zHA=; h=From:To:Cc:Subject:Date:Reply-to:From; b=UDLg0Bw4rmircH1sD9fcA4U7vR53DUPIAam0TiP85KQHwkyZbwzU5jeRgNWngx2e2 z0IWpvtc2rJf5GgMlSyEjvxKu13xWQQwSdiANQyd1zxeEw0LHP8Q0fKbRS4lSBwDhx lMbodpHOqUwtix+IMH200kcsvOjUN07tMM6/jnO0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2022-49493: ASoC: rt5645: Fix errorenous cleanup order Date: Wed, 26 Feb 2025 03:12:47 +0100 Message-ID: <2025022606-CVE-2022-49493-a2ff@gregkh> X-Mailer: git-send-email 2.48.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=3239; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=8zAFLRHLBImssd3aYrvLb7ISxNPa1CLxbzmk34T3zHA=; b=owGbwMvMwCRo6H6F97bub03G02pJDOn7yv9N3pr0pPqG4FSFfV+vlJg+Z218Vr08dJ9vhAiPY 0DExQCejlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZiIrhTDXHm9j623mmtdbl6z aSjU7Gh+2Ms3n2F+6Jn9B53nqHTefxFSFb2jhLnz49PXAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: ASoC: rt5645: Fix errorenous cleanup order There is a logic error when removing rt5645 device as the function rt5645_i2c_remove() first cancel the &rt5645->jack_detect_work and delete the &rt5645->btn_check_timer latter. However, since the timer handler rt5645_btn_check_callback() will re-queue the jack_detect_work, this cleanup order is buggy. That is, once the del_timer_sync in rt5645_i2c_remove is concurrently run with the rt5645_btn_check_callback, the canceled jack_detect_work will be rescheduled again, leading to possible use-after-free. This patch fix the issue by placing the del_timer_sync function before the cancel_delayed_work_sync. The Linux kernel CVE team has assigned CVE-2022-49493 to this issue. Affected and fixed versions =========================== Fixed in 4.9.318 with commit 7d801e807536a9a9c2146c5f4a5836f154517ed3 Fixed in 4.14.283 with commit 236d29c5857f02e0a53fdf15d3dce1536c4322ce Fixed in 4.19.247 with commit 0941150100173d4eaf3fe08ff4b16740e7c3026f Fixed in 5.4.198 with commit abe7554da62cb489712a54de69ef5665c250e564 Fixed in 5.10.121 with commit 1a5a3dfd9f172dcb115072f0aea5e27d3083c20e Fixed in 5.15.46 with commit 061a6159cea583f1155f67d1915917a6b9282662 Fixed in 5.17.14 with commit 88c09e4812d72c3153afc8e5a45ecac2d0eae3ff Fixed in 5.18.3 with commit 453f0920ffc1a28e28ddb9c3cd5562472b2895b0 Fixed in 5.19 with commit 2def44d3aec59e38d2701c568d65540783f90f2f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2022-49493 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: sound/soc/codecs/rt5645.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/7d801e807536a9a9c2146c5f4a5836f154517ed3 https://git.kernel.org/stable/c/236d29c5857f02e0a53fdf15d3dce1536c4322ce https://git.kernel.org/stable/c/0941150100173d4eaf3fe08ff4b16740e7c3026f https://git.kernel.org/stable/c/abe7554da62cb489712a54de69ef5665c250e564 https://git.kernel.org/stable/c/1a5a3dfd9f172dcb115072f0aea5e27d3083c20e https://git.kernel.org/stable/c/061a6159cea583f1155f67d1915917a6b9282662 https://git.kernel.org/stable/c/88c09e4812d72c3153afc8e5a45ecac2d0eae3ff https://git.kernel.org/stable/c/453f0920ffc1a28e28ddb9c3cd5562472b2895b0 https://git.kernel.org/stable/c/2def44d3aec59e38d2701c568d65540783f90f2f