SB20241022278 - Resource management error in Linux kernel events
Published: October 22, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2022-48950)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the event_sched_out(), group_sched_out(), __perf_remove_from_context(), perf_event_release_kernel() and perf_pending_task() functions in kernel/events/core.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/8bffa95ac19ff27c8261904f89d36c7fcf215d59
- https://git.kernel.org/stable/c/78e1317a174edbfd1182599bf76c092a2877672c
- https://git.kernel.org/stable/c/517e6a301f34613bff24a8e35b5455884f2d83d8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.84
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1