From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 450D02153F3 for ; Wed, 26 Feb 2025 02:13:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740535996; cv=none; b=kMjaW0QmjcO6mrvBeoqTzJvLQ1rxJWpqt+7bEIT3axWK+JrTEUR/BQRNqJg2DUh4iV8purtqKflMOnEWBG+1l/ufJx0XTGL1h1b0g5y7bsefMELWPVZjTXYJXGJdFofCaTvh9Be+NzW+fk59JIo3f69nmw5HCXxvxln+s9jYkpo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740535996; c=relaxed/simple; bh=6v4cOPEzbmTvQzHAlOFrAzGSoKXVCef+kIP1uLc6Yvs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=qYTxqyiecT2JzgH8oysdurd4jfN7JgUpQAErrG2tqcSc8fJeM6aRmI4F6VxMTD0gcqGSIh9X9Xi2CPcwfkYKqrKtEMbuqgnPNxADsvR/Dz1PACmJR/8VW0vpK0bfbGx4OhU8gHaqXIp/ZpwBcz4NaHXrF0P5gQ10KDbdRaWxzeM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=1Ymn1d5B; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="1Ymn1d5B" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 12B42C4CEEB; Wed, 26 Feb 2025 02:13:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1740535996; bh=6v4cOPEzbmTvQzHAlOFrAzGSoKXVCef+kIP1uLc6Yvs=; h=From:To:Cc:Subject:Date:Reply-to:From; b=1Ymn1d5ByuLK2XwPATDhilNhXzot/4v4fCaawBysMMrx3pwen4x7Fv6eJ9k3fPXPh rGx47M8CtrbVJtcXfctI73zRKB6Lb3tA/wYbzT1Skyt8roBQfUDyQL/3kr8n4q6OwR MgdoeFUuPdxyoTS9pdfiDlObGRyJGMUVt8qt5M7E= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2022-49350: net: mdio: unexport __init-annotated mdio_bus_init() Date: Wed, 26 Feb 2025 03:10:24 +0100 Message-ID: <2025022642-CVE-2022-49350-c5d2@gregkh> X-Mailer: git-send-email 2.48.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=3778; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=6v4cOPEzbmTvQzHAlOFrAzGSoKXVCef+kIP1uLc6Yvs=; b=owGbwMvMwCRo6H6F97bub03G02pJDOn7yp9NWPRgxXy+9WfCq2MK87Pn1m7jCtrYL+H182X+h 7rSudtsO2JZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAi77oZFhzZ1vPxxbK+5Hu/ S66/Kuh531VzZALDPM3zQv5zmI88Fou7fG7DFm6TLZaHZgEA X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: net: mdio: unexport __init-annotated mdio_bus_init() EXPORT_SYMBOL and __init is a bad combination because the .init.text section is freed up after the initialization. Hence, modules cannot use symbols annotated __init. The access to a freed symbol may end up with kernel panic. modpost used to detect it, but it has been broken for a decade. Recently, I fixed modpost so it started to warn it again, then this showed up in linux-next builds. There are two ways to fix it: - Remove __init - Remove EXPORT_SYMBOL I chose the latter for this case because the only in-tree call-site, drivers/net/phy/phy_device.c is never compiled as modular. (CONFIG_PHYLIB is boolean) The Linux kernel CVE team has assigned CVE-2022-49350 to this issue. Affected and fixed versions =========================== Issue introduced in 4.12 with commit 90eff9096c01ba90cdae504a6b95ee87fe2556a3 and fixed in 4.14.283 with commit ab64ec2c75683f30ccde9eaaf0761002f901aa12 Issue introduced in 4.12 with commit 90eff9096c01ba90cdae504a6b95ee87fe2556a3 and fixed in 4.19.247 with commit 5534bcd7c40299862237c4a8fd9c5031b3db1538 Issue introduced in 4.12 with commit 90eff9096c01ba90cdae504a6b95ee87fe2556a3 and fixed in 5.4.198 with commit 6a90a44d53428a3bf01bd80df9ba78b19959270c Issue introduced in 4.12 with commit 90eff9096c01ba90cdae504a6b95ee87fe2556a3 and fixed in 5.10.122 with commit 7759c3222815b945a94b212bc0c6cdec475cfec2 Issue introduced in 4.12 with commit 90eff9096c01ba90cdae504a6b95ee87fe2556a3 and fixed in 5.15.47 with commit 59fa94cddf9eef8d8dae587373eed8b8f4eb11d7 Issue introduced in 4.12 with commit 90eff9096c01ba90cdae504a6b95ee87fe2556a3 and fixed in 5.17.15 with commit f5c68137f1191ba3fcf6260ec71b30be2e2bf4c3 Issue introduced in 4.12 with commit 90eff9096c01ba90cdae504a6b95ee87fe2556a3 and fixed in 5.18.4 with commit f2f0f8c18b60ca64ff50892ed899cf1c77864755 Issue introduced in 4.12 with commit 90eff9096c01ba90cdae504a6b95ee87fe2556a3 and fixed in 5.19 with commit 35b42dce619701f1300fb8498dae82c9bb1f0263 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2022-49350 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/phy/mdio_bus.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/ab64ec2c75683f30ccde9eaaf0761002f901aa12 https://git.kernel.org/stable/c/5534bcd7c40299862237c4a8fd9c5031b3db1538 https://git.kernel.org/stable/c/6a90a44d53428a3bf01bd80df9ba78b19959270c https://git.kernel.org/stable/c/7759c3222815b945a94b212bc0c6cdec475cfec2 https://git.kernel.org/stable/c/59fa94cddf9eef8d8dae587373eed8b8f4eb11d7 https://git.kernel.org/stable/c/f5c68137f1191ba3fcf6260ec71b30be2e2bf4c3 https://git.kernel.org/stable/c/f2f0f8c18b60ca64ff50892ed899cf1c77864755 https://git.kernel.org/stable/c/35b42dce619701f1300fb8498dae82c9bb1f0263