CVE-2022-48988 Details
Description
In the Linux kernel, the following vulnerability has been resolved: memcg: fix possible use-after-free in memcg_write_event_control() memcg_write_event_control() accesses the dentry->d_name of the specified control fd to route the write call. As a cgroup interface file can't be renamed, it's safe to access d_name as long as the specified file is a regular cgroup file. Also, as these cgroup interface files can't be removed before the directory, it's safe to access the parent too. Prior to 347c4a874710 ("memcg: remove cgroup_event->cft"), there was a call to __file_cft() which verified that the specified file is a regular cgroupfs file before further accesses. The cftype pointer returned from __file_cft() was no longer necessary and the commit inadvertently dropped the file type check with it allowing any file to slip through. With the invarients broken, the d_name and parent accesses can now race against renames and removals of arbitrary files and cause use-after-free's. Fix the bug by resurrecting the file type check in __file_cft(). Now that cgroupfs is implemented through kernfs, checking the file operations needs to go through a layer of indirection. Instead, let's check the superblock and dentry type.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 22, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0ed074317b835caa6c03bcfa8f133365324673dc | kernel.org | Patch |
| https://git.kernel.org/stable/c/35963b31821920908e397146502066f6b032c917 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4a7ba45b1a435e7097ca0f79a847d0949d0eb088 | kernel.org | Patch |
| https://git.kernel.org/stable/c/aad8bbd17a1d586005feb9226c2e9cfce1432e13 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b77600e26fd48727a95ffd50ba1e937efb548125 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e1ae97624ecf400ea56c238bff23e5cd139df0b8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f1f7f36cf682fa59db15e2089039a2eeb58ff2ad | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.14, < 4.14.302 >= 4.15, < 4.19.269 >= 4.20, < 5.4.227 >= 5.5, < 5.10.159 >= 5.11, < 5.15.83 >= 5.16, < 6.0.13 6.1 rc1 6.1 rc2 6.1 rc3 6.1 rc4 6.1 rc5 6.1 rc6 6.1 rc7 6.1 rc8 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 1, 2024 | Initial Analysis | [email protected] |
| Oct 21, 2024 | New CVE Received | kernel.org |