memcg: fix possible use-after-free in memcg_write_event_control()
Summary
| CVE | CVE-2022-48988 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-10-21 20:15:10 UTC |
| Updated | 2026-08-04 10:17:29 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: memcg: fix possible use-after-free in memcg_write_event_control() memcg_write_event_control() accesses the dentry->d_name of the specified control fd to route the write call. As a cgroup interface file can't be renamed, it's safe to access d_name as long as the specified file is a regular cgroup file. Also, as these cgroup interface files can't be removed before the directory, it's safe to access the parent too. Prior to 347c4a874710 ("memcg: remove cgroup_event->cft"), there was a call to __file_cft() which verified that the specified file is a regular cgroupfs file before further accesses. The cftype pointer returned from __file_cft() was no longer necessary and the commit inadvertently dropped the file type check with it allowing any file to slip through. With the invarients broken, the d_name and parent accesses can now race against renames and removals of arbitrary files and cause use-after-free's. Fix the bug by resurrecting the file type check in __file_cft(). Now that cgroupfs is implemented through kernfs, checking the file operations needs to go through a layer of indirection. Instead, let's check the superblock and dentry type. |
Risk And Classification
Primary CVSS: v3.1 7 HIGH from [email protected]
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-416
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 347c4a8747104a945ecced358944e42879176ca5 b77600e26fd48727a95ffd50ba1e937efb548125 git | Not specified |
| CNA | Linux | Linux | affected 347c4a8747104a945ecced358944e42879176ca5 e1ae97624ecf400ea56c238bff23e5cd139df0b8 git | Not specified |
| CNA | Linux | Linux | affected 347c4a8747104a945ecced358944e42879176ca5 35963b31821920908e397146502066f6b032c917 git | Not specified |
| CNA | Linux | Linux | affected 347c4a8747104a945ecced358944e42879176ca5 f1f7f36cf682fa59db15e2089039a2eeb58ff2ad git | Not specified |
| CNA | Linux | Linux | affected 347c4a8747104a945ecced358944e42879176ca5 aad8bbd17a1d586005feb9226c2e9cfce1432e13 git | Not specified |
| CNA | Linux | Linux | affected 347c4a8747104a945ecced358944e42879176ca5 0ed074317b835caa6c03bcfa8f133365324673dc git | Not specified |
| CNA | Linux | Linux | affected 347c4a8747104a945ecced358944e42879176ca5 4a7ba45b1a435e7097ca0f79a847d0949d0eb088 git | Not specified |
| CNA | Linux | Linux | affected 3.14 | Not specified |
| CNA | Linux | Linux | unaffected 3.14 semver | Not specified |
| CNA | Linux | Linux | unaffected 4.14.302 4.14.* semver | Not specified |
| CNA | Linux | Linux | unaffected 4.19.269 4.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.227 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.159 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.83 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.0.13 6.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/b77600e26fd48727a95ffd50ba1e937efb548125 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/0ed074317b835caa6c03bcfa8f133365324673dc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/4a7ba45b1a435e7097ca0f79a847d0949d0eb088 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/35963b31821920908e397146502066f6b032c917 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/f1f7f36cf682fa59db15e2089039a2eeb58ff2ad | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/aad8bbd17a1d586005feb9226c2e9cfce1432e13 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/e1ae97624ecf400ea56c238bff23e5cd139df0b8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.