CVE-2022-49133
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49133 affects the Linux kernel, specifically in the drm/amdkfd component. The vulnerability involves a deadlock condition that occurs when a process exits while handling svm range restore work. This issue was discovered in the kfdprocessnotifierrelease function which flushes svmrangerestorework, potentially leading to a deadlock situation when deferred_list work releases the last user (Kernel Git).

Technical details

The vulnerability occurs in the kfdprocessnotifierrelease function when it attempts to flush svmrangerestorework. The deadlock happens because if deferredlist work mmput releases the last user, it triggers a call sequence through exitmmap -> notifierrelease. The issue manifests in the following call trace: waitforcompletion -> _flushwork -> _cancelworktimer -> canceldelayedworksync -> kfdprocessnotifierrelease -> _mmunotifierrelease -> exitmmap -> mmput -> svmrangedeferredlistwork -> processonework (Kernel Git).

Impact

The vulnerability can result in a system deadlock when a process exits while handling svm range restore work, potentially affecting system stability and performance (Ubuntu Security).

Mitigation and workarounds

The issue has been fixed by moving the flush svmrangerestorework operation to kfdprocesswqrelease to avoid the deadlock. Additionally, svmrangerestore_work now takes a task->mm reference to prevent the memory management structure from being released while validating and mapping ranges to GPU (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-riscv
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-azure-5.4
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-debug-uki-virt-addons
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • rtla
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management