CVE-2022-48745: Linux Kernel
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Use del_timer_sync in fw reset flow of halting poll Substitute del_timer() with del_timer_sync() in fw reset polling deactivation flow, in order to prevent a race condition which occurs when del_timer() is called and timer is deactivated while another process is handling the timer interrupt. A situation that led to the following call trace: RIP: 0010:run_timer_softirq+0x137/0x420 <IRQ> recalibrate_cpu_khz+0x10/0x10 ktime_get+0x3e/0xa0 ? sched_clock_cpu+0xb/0xc0 __do_softirq+0xf5/0x2ea irq_exit_rcu+0xc1/0xf0 sysvec_apic_timer_interrupt+0x9e/0xc0 asm_sysvec_apic_timer_interrupt+0x12/0x20 </IRQ>
Affected products
- Linux Linux Kernel: from 5.10, before 5.10.97 (fixed in 5.10.97); from 5.11, before 5.15.20 (fixed in 5.15.20); from 5.16, before 5.16.6 (fixed in 5.16.6); version 5.17 only
Published 2024-06-20. Last modified 2026-06-17.