CVE-2022-49452: dpaa2-eth: retrieve the virtual address before dma_unmap
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-eth: retrieve the virtual address before dma_unmap
The TSO header was DMA unmapped before the virtual address was retrieved
and then used to free the buffer. This meant that we were actually
removing the DMA map and then trying to search for it to help in
retrieving the virtual address. This lead to a invalid virtual address
being used in the kfree call.
Fix this by calling dpaa2_iova_to_virt() prior to the dma_unmap call.
[ 487.231819] Unable to handle kernel paging request at virtual address fffffd9807000008
(...)
[ 487.354061] Hardware name: SolidRun LX2160A Honeycomb (DT)
[ 487.359535] pstate: a0400005 (NzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 487.366485] pc : kfree+0xac/0x304
[ 487.369799] lr : kfree+0x204/0x304
[ 487.373191] sp : ffff80000c4eb120
[ 487.376493] x29: ffff80000c4eb120 x28: ffff662240c46400 x27: 0000000000000001
[ 487.383621] x26: 0000000000000001 x25: ffff662246da0cc0 x24: ffff66224af78000
[ 487.390748] x23: ffffad184f4ce008 x22: ffffad1850185000 x21: ffffad1838d13cec
[ 487.397874] x20: ffff6601c0000000 x19: fffffd9807000000 x18: 0000000000000000
[ 487.405000] x17: ffffb910cdc49000 x16: ffffad184d7d9080 x15: 0000000000004000
[ 487.412126] x14: 0000000000000008 x13: 000000000000ffff x12: 0000000000000000
[ 487.419252] x11: 0000000000000004 x10: 0000000000000001 x9 : ffffad184d7d927c
[ 487.426379] x8 : 0000000000000000 x7 : 0000000ffffffd1d x6 : ffff662240a94900
[ 487.433505] x5 : 0000000000000003 x4 : 0000000000000009 x3 : ffffad184f4ce008
[ 487.440632] x2 : ffff662243eec000 x1 : 0000000100000100 x0 : fffffc0000000000
[ 487.447758] Call trace:
[ 487.450194] kfree+0xac/0x304
[ 487.453151] dpaa2_eth_free_tx_fd.isra.0+0x33c/0x3e0 [fsl_dpaa2_eth]
[ 487.459507] dpaa2_eth_tx_conf+0x100/0x2e0 [fsl_dpaa2_eth]
[ 487.464989] dpaa2_eth_poll+0xdc/0x380 [fsl_dpaa2_eth]
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel driver memory-handling bug in the dpaa2-eth Ethernet driver. The source shows an invalid virtual address being freed, causing a kernel paging fault. Business impact is primarily availability risk on systems using this driver and affected kernel builds.
Executive priority
Treat as targeted kernel stability risk, not a confirmed internet-wide emergency. Prioritize remediation where affected Linux kernels run on DPAA2 Ethernet platforms, especially production network appliances or embedded systems requiring high availability.
Technical view
The TSO header buffer was DMA-unmapped before its virtual address was retrieved. The driver then attempted lookup after unmap and passed an invalid virtual address to kfree. The fix retrieves the virtual address with dpaa2_iova_to_virt() before dma_unmap().
Likely exposure
Exposure appears limited to Linux systems using the fsl_dpaa2_eth/dpaa2-eth driver on compatible DPAA2 Ethernet hardware, with affected 5.18-era kernels identified in the CVE data. The source bundle does not prove broader product exposure.
Exploitation context
The bundle reports no KEV listing and provides no cited evidence of active exploitation. It includes a kernel crash trace, suggesting practical impact may be local or traffic-triggered denial of service, but exploitation conditions are not fully documented.
Researcher notes
Evidence is sparse: no CVSS, CWE, exploit status, or detailed trigger conditions are provided. The technical root cause and fix direction are clear from the kernel description and stable commit references, but exposure assessment depends on hardware, driver use, and kernel branch.
Mitigation direction
Apply vendor or distribution kernel updates containing the referenced stable fixes.
Prioritize systems using DPAA2 Ethernet hardware and the dpaa2-eth driver.
For custom kernels, verify the referenced kernel.org fixes are included.
Monitor kernel logs for dpaa2_eth and kfree paging fault traces.
Validation and detection
Inventory Linux hosts using fsl_dpaa2_eth or DPAA2 Ethernet hardware.
Compare running kernel versions against vendor advisories and fixed kernel builds.
Check custom kernel trees for the two referenced stable commits.
Review crash logs for dpaa2_eth_free_tx_fd, dpaa2_eth_tx_conf, or kfree faults.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49452 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
3Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Feb 26, 2025, 02:13 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.