SB2025062064 - Improper locking in Linux kernel hisilicon sec2 driver
Published: June 20, 2025 Updated: June 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-50171)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the sec_alloc_req_id(), sec_free_req_id(), sec_bd_send(), sec_create_qp_ctx() and sec_back_req_clear() functions in drivers/crypto/hisilicon/sec2/sec_crypto.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/02884a4f12de11f54d4ca67a07dd1f111d96fdbd
- https://git.kernel.org/stable/c/16e18a8ac7c9748cf35a8d2f0ba2c6e8850e7568
- https://git.kernel.org/stable/c/4a461ba5b9753352f438824fdd915cba675b1733
- https://git.kernel.org/stable/c/aa495dfe71229b9034b59d8072ff0b2325ddd5ee
- https://git.kernel.org/stable/c/c9be45e4c69fde36522274f04d1aa0d097ae3958
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.2