SB20250226482 - Improper locking in Linux kernel trace
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-49402)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the ftrace_func_mapper_add_ip() and register_ftrace_direct() functions in kernel/trace/ftrace.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/7d54c15cb89a29a5f59e5ffc9ee62e6591769ef1
- https://git.kernel.org/stable/c/805e87af946d8d2954171361e64d143ff37a441b
- https://git.kernel.org/stable/c/82c888e51c2176a06f8b4541cf748ee81aac6e7e
- https://git.kernel.org/stable/c/a0392833a178cf109a57c2a9d4d531bdfc6cd98f
- https://git.kernel.org/stable/c/cae2978d6907ef2c08b9b15f704e783f7c284713
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.46