SB20241022116 - Improper locking in Linux kernel char tpm driver
Published: October 22, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-48997)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the tpm_pm_suspend() function in drivers/char/tpm/tpm-interface.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/d699373ac5f3545243d3c73a1ccab77fdef8cec6
- https://git.kernel.org/stable/c/4e0d6c687c925e27fd4bc78a2721d10acf5614d6
- https://git.kernel.org/stable/c/571b6bbbf54d835ea6120f65575cb55cd767e603
- https://git.kernel.org/stable/c/25b78bf98b07ff5aceb9b1e24f72ec0236c5c053
- https://git.kernel.org/stable/c/23393c6461422df5bf8084a086ada9a7e17dc2ba
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.158
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.82
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.226
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1