CVE-2022-49434 Details
Description
In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store() The sysfs sriov_numvfs_store() path acquires the device lock before the config space access lock: sriov_numvfs_store device_lock # A (1) acquire device lock sriov_configure vfio_pci_sriov_configure # (for example) vfio_pci_core_sriov_configure pci_disable_sriov sriov_disable pci_cfg_access_lock pci_wait_cfg # B (4) wait for dev->block_cfg_access == 0 Previously, pci_dev_lock() acquired the config space access lock before the device lock: pci_dev_lock pci_cfg_access_lock dev->block_cfg_access = 1 # B (2) set dev->block_cfg_access = 1 device_lock # A (3) wait for device lock Any path that uses pci_dev_lock(), e.g., pci_reset_function(), may deadlock with sriov_numvfs_store() if the operations occur in the sequence (1) (2) (3) (4). Avoid the deadlock by reversing the order in pci_dev_lock() so it acquires the device lock before the config space access lock, the same as the sriov_numvfs_store() path. [bhelgaas: combined and adapted commit log from Jay Zhou's independent subsequent posting: https://lore.kernel.org/r/[email protected]]
A deadlock vulnerability has been identified in the Linux kernel's PCI subsystem, specifically within the SR-IOV (Single Root I/O Virtualization) configuration process. The issue arises because the sysfs 'sriov_numvfs_store' function acquires the device lock before the configuration space access lock. This can lead to a deadlock when 'sriov_numvfs_store' is called after 'pci_dev_lock', which waits for the device lock, creating a circular dependency.
The vulnerability has been addressed by reversing the order in which locks are acquired, ensuring that the device lock is obtained before the configuration space access lock. Users should apply the latest patches available in the Linux kernel to mitigate this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2cdd5284035322795b0964f899eefba254cfe483 | kernel.org | Patch |
| https://git.kernel.org/stable/c/59ea6b3ae51df7cd6bfd84c9c0030609b9315622 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a91ee0e9fca9d7501286cfbced9b30a33e52740a | kernel.org | Patch |
| https://git.kernel.org/stable/c/aed6d4d519210c28817948f34c53b6e058e0456c | kernel.org | Patch |
| https://git.kernel.org/stable/c/c3c6dc1853b8bf3c718f96fd8480a6eb09ba4831 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c9a81f9ed6ae3554621d6a50220b1bc74b67d81e | kernel.org | Patch |
| https://git.kernel.org/stable/c/ea047f51172aa68841adef7f52d375002438b8f0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/eff3587b9c01439b738298475e555c028ac9f55e | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-667 | Improper Locking | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.9.318 >= 4.10, < 4.14.283 >= 4.15, < 4.19.247 >= 4.20, < 5.4.198 >= 5.5, < 5.10.121 >= 5.11, < 5.15.46 >= 5.16, < 5.17.14 >= 5.18, < 5.18.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 23, 2025 | CVE Modified | kernel.org |
| Oct 22, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | kernel.org |