CVE-2022-48816
Executive Summary
A race condition in the Linux kernel’s SUNRPC subsystem allows an attacker to trigger a kernel oops during a sysfs read if the RPC socket is asynchronously set to NULL without holding the recv_mutex. The patch narrows but does not eliminate the window, leaving the kernel vulnerable to a denial‑of‑service crash.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2024-07-16T12:15:05.687 - Last Modified: 2026-10-03T11:17:25.280
Original Description: In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: lock against ->sock changing during sysfs read
->sock can be set to NULL asynchronously unless ->recv_mutex is held. So it is important to hold that mutex. Otherwise a sysfs read can trigger an oops. Commit 17f09d3f619a ("SUNRPC: Check if the xprt is connected before handling sysfs reads") appears to attempt to fix this problem, but it only narrows the race window.
"Your work is to discover your world and then with all your heart give yourself to it."
— Buddha