Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2022-48799
HistoryJul 16, 2024 - 11:43 a.m.

CVE-2022-48799 perf: Fix list corruption in perf_cgroup_switch()

2024-07-1611:43:52
Linux
github.com
3
vulnerability
list corruption
perf_cgroup_switch
linux kernel

AI Score

6.9

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

perf: Fix list corruption in perf_cgroup_switch()

There’s list corruption on cgrp_cpuctx_list. This happens on the
following path:

perf_cgroup_switch: list_for_each_entry(cgrp_cpuctx_list)
cpu_ctx_sched_in
ctx_sched_in
ctx_pinned_sched_in
merge_sched_in
perf_cgroup_event_disable: remove the event from the list

Use list_for_each_entry_safe() to allow removing an entry during
iteration.

AI Score

6.9

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial