SB2025062057 - Improper locking in Linux kernel rcu
Published: June 20, 2025 Updated: June 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-50177)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the rcutorture_booster_init() and rcu_torture_init() functions in kernel/rcu/rcutorture.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3002153a91a9732a6d1d0bb95138593c7da15743
- https://git.kernel.org/stable/c/621595f771a6bd458ffbc40679e222ba5d0a7a1e
- https://git.kernel.org/stable/c/7e7472c62c6ded322afd9d5ac8bb20a08e7c5674
- https://git.kernel.org/stable/c/8e84693621f53bf894af9905a6531e0530402145
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.18