SB20250226573 - Double free in Linux kernel clocksource driver
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double free (CVE-ID: CVE-2022-49726)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the hv_init_clocksource() function in drivers/clocksource/hyperv_timer.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0414eab7c78f3518143d383e448d44fc573ac6d2
- https://git.kernel.org/stable/c/245b993d8f6c4e25f19191edfbd8080b645e12b1
- https://git.kernel.org/stable/c/937fcbb55a1e48a6422e87e8f49422c92265f102
- https://git.kernel.org/stable/c/cff3a7ce6e81418b6e8bac941779bbf5d342d626
- https://git.kernel.org/stable/c/db965e2757d95f695e606856418cd84003dd036d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.124