cbcvebase.
CVE-2022-48931
published 2024-08-22

CVE-2022-48931: In the Linux kernel, the following vulnerability has been resolved: configfs: fix a race in configfs_{,un}register_subsystem() When…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.17%
6.2th percentile
In the Linux kernel, the following vulnerability has been resolved: configfs: fix a race in configfs_{,un}register_subsystem() When configfs_register_subsystem() or configfs_unregister_subsystem() is executing link_group() or unlink_group(), it is possible that two processes add or delete list concurrently. Some unfortunate interleavings of them can cause kernel panic. One of cases is: A --> B --> C --> D A prev = prev | | next->prev = prev prev->next = next | | // prev == B | prev->next = next Fix this by adding mutex when calling link_group() or unlink_group(), but parent configfs_subsystem is NULL when config_item is root. So I create a mutex configfs_subsystem_mutex.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.12-1 (bookworm)linux 5.16.12-1 (bookworm)
linuxlinux
linuxlinux>= 7063fbf2261194f72ee75afca67b3b38b554b5fa < 40805099af11f68c5ca7dbcfacf455da8f99f62240805099af11f68c5ca7dbcfacf455da8f99f622
linuxlinux>= 7063fbf2261194f72ee75afca67b3b38b554b5fa < d1654de19d42f513b6cfe955cc77e7f427e05a77d1654de19d42f513b6cfe955cc77e7f427e05a77
linuxlinux>= 7063fbf2261194f72ee75afca67b3b38b554b5fa < a37024f7757c25550accdebf49e497ad6ae239fea37024f7757c25550accdebf49e497ad6ae239fe
linuxlinux>= 7063fbf2261194f72ee75afca67b3b38b554b5fa < b7e2b91fcb5c78c414e33dc8d50642e307ca0c5ab7e2b91fcb5c78c414e33dc8d50642e307ca0c5a
linuxlinux>= 7063fbf2261194f72ee75afca67b3b38b554b5fa < a7ab53d3c27dfe83bb594456b9f38a37796ec39ba7ab53d3c27dfe83bb594456b9f38a37796ec39b
linuxlinux>= 7063fbf2261194f72ee75afca67b3b38b554b5fa < e7a66dd2687758718eddd79b542a95cf3aa488cce7a66dd2687758718eddd79b542a95cf3aa488cc
linuxlinux>= 7063fbf2261194f72ee75afca67b3b38b554b5fa < 3aadfd46858b1f64d4d6a0654b863e21aabff9753aadfd46858b1f64d4d6a0654b863e21aabff975
linuxlinux>= 7063fbf2261194f72ee75afca67b3b38b554b5fa < 84ec758fb2daa236026506868c8796b0500c047d84ec758fb2daa236026506868c8796b0500c047d
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 2.6.16 < 4.9.3044.9.304
linuxlinux_kernel>= 4.10 < 4.14.2694.14.269
linuxlinux_kernel>= 4.15 < 4.19.2324.19.232
linuxlinux_kernel>= 4.20 < 5.4.1825.4.182
linuxlinux_kernel>= 5.11 < 5.15.265.15.26
linuxlinux_kernel>= 5.16 < 5.16.125.16.12
linuxlinux_kernel>= 5.5 < 5.10.1035.10.103

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.