CVE-2022-48675 is a nested deadlock vulnerability in the Linux kernel's InfiniBand (IB) core, specifically within the On-Demand Paging (ODP) flow. This flaw occurs when the mmput() function is called while the umem_odp->umem_mutex is locked, potentially leading to a deadlock during memory management operations. The issue affects Linux kernel versions and has been resolved by using mmput_async() to defer the problematic call to a separate task. The vulnerability has a CVSSv3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity and requiring low privileges. Its potential impact is high availability, as it can cause a system deadlock. There is no impact on confidentiality or integrity. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10, < 5.10.143CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.68CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.19.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.