CVE-2022-48950
Description
In the Linux kernel, the following vulnerability has been resolved:
perf: Fix perf_pending_task() UaF
Per syzbot it is possible for perf_pending_task() to run after the event is free()'d. There are two related but distinct cases:
- the task_work was already queued before destroying the event;
- destroying the event itself queues the task_work.
The first cannot be solved using task_work_cancel() since perf_release() itself might be called from a task_work (____fput), which means the current->task_works list is already empty and task_work_cancel() won't be able to find the perf_pending_task() entry.
The simplest alternative is extending the perf_event lifetime to cover the task_work.
The second is just silly, queueing a task_work while you know the event is going away makes no sense and is easily avoided by re-arranging how the event is marked STATE_DEAD and ensuring it goes through STATE_OFF on the way down.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12(expand)+ 10 more
- (no CPE)
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <5.15.84
- cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.1:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.1:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.1:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.1:rc7:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.1:rc8:*:*:*:*:*:*
- (no CPE)range: 5.15.77
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.