memcg: fix possible use-after-free in memcg_write_event_control()

Summary

CVECVE-2022-48988
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-10-21 20:15:10 UTC
Updated2026-08-04 10:17:29 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: memcg: fix possible use-after-free in memcg_write_event_control() memcg_write_event_control() accesses the dentry->d_name of the specified control fd to route the write call. As a cgroup interface file can't be renamed, it's safe to access d_name as long as the specified file is a regular cgroup file. Also, as these cgroup interface files can't be removed before the directory, it's safe to access the parent too. Prior to 347c4a874710 ("memcg: remove cgroup_event->cft"), there was a call to __file_cft() which verified that the specified file is a regular cgroupfs file before further accesses. The cftype pointer returned from __file_cft() was no longer necessary and the commit inadvertently dropped the file type check with it allowing any file to slip through. With the invarients broken, the d_name and parent accesses can now race against renames and removals of arbitrary files and cause use-after-free's. Fix the bug by resurrecting the file type check in __file_cft(). Now that cgroupfs is implemented through kernfs, checking the file operations needs to go through a layer of indirection. Instead, let's check the superblock and dentry type.

Risk And Classification

Primary CVSS: v3.1 7 HIGH from [email protected]

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem Types: CWE-416


VersionSourceTypeScoreSeverityVector
3.1[email protected]Primary7HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 347c4a8747104a945ecced358944e42879176ca5 b77600e26fd48727a95ffd50ba1e937efb548125 git Not specified
CNA Linux Linux affected 347c4a8747104a945ecced358944e42879176ca5 e1ae97624ecf400ea56c238bff23e5cd139df0b8 git Not specified
CNA Linux Linux affected 347c4a8747104a945ecced358944e42879176ca5 35963b31821920908e397146502066f6b032c917 git Not specified
CNA Linux Linux affected 347c4a8747104a945ecced358944e42879176ca5 f1f7f36cf682fa59db15e2089039a2eeb58ff2ad git Not specified
CNA Linux Linux affected 347c4a8747104a945ecced358944e42879176ca5 aad8bbd17a1d586005feb9226c2e9cfce1432e13 git Not specified
CNA Linux Linux affected 347c4a8747104a945ecced358944e42879176ca5 0ed074317b835caa6c03bcfa8f133365324673dc git Not specified
CNA Linux Linux affected 347c4a8747104a945ecced358944e42879176ca5 4a7ba45b1a435e7097ca0f79a847d0949d0eb088 git Not specified
CNA Linux Linux affected 3.14 Not specified
CNA Linux Linux unaffected 3.14 semver Not specified
CNA Linux Linux unaffected 4.14.302 4.14.* semver Not specified
CNA Linux Linux unaffected 4.19.269 4.19.* semver Not specified
CNA Linux Linux unaffected 5.4.227 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.159 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.83 5.15.* semver Not specified
CNA Linux Linux unaffected 6.0.13 6.0.* semver Not specified
CNA Linux Linux unaffected 6.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/b77600e26fd48727a95ffd50ba1e937efb548125 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/0ed074317b835caa6c03bcfa8f133365324673dc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/4a7ba45b1a435e7097ca0f79a847d0949d0eb088 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/35963b31821920908e397146502066f6b032c917 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/f1f7f36cf682fa59db15e2089039a2eeb58ff2ad 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/aad8bbd17a1d586005feb9226c2e9cfce1432e13 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/e1ae97624ecf400ea56c238bff23e5cd139df0b8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report