VYPR
High severity7.8NVD Advisory· Published Oct 21, 2024· Updated Aug 4, 2026

CVE-2022-48950

CVE-2022-48950

Description

In the Linux kernel, the following vulnerability has been resolved:

perf: Fix perf_pending_task() UaF

Per syzbot it is possible for perf_pending_task() to run after the event is free()'d. There are two related but distinct cases:

  • the task_work was already queued before destroying the event;
  • destroying the event itself queues the task_work.

The first cannot be solved using task_work_cancel() since perf_release() itself might be called from a task_work (____fput), which means the current->task_works list is already empty and task_work_cancel() won't be able to find the perf_pending_task() entry.

The simplest alternative is extending the perf_event lifetime to cover the task_work.

The second is just silly, queueing a task_work while you know the event is going away makes no sense and is easily avoided by re-arranging how the event is marked STATE_DEAD and ensuring it goes through STATE_OFF on the way down.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • Linux/Kernelllm-fuzzy11 versions
    (expand)+ 10 more
    • (no CPE)
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <5.15.84
    • cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc7:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc8:*:*:*:*:*:*
    • (no CPE)range: 5.15.77
  • osv-coords
    Range: >= 5.15.77, < 5.15.84

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.