cbcvebase.
CVE-2022-49647
published 2025-02-26

CVE-2022-49647: In the Linux kernel, the following vulnerability has been resolved: cgroup: Use separate src/dst nodes when preloading css_sets for migration Each cset…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.2th percentile
In the Linux kernel, the following vulnerability has been resolved: cgroup: Use separate src/dst nodes when preloading css_sets for migration Each cset (css_set) is pinned by its tasks. When we're moving tasks around across csets for a migration, we need to hold the source and destination csets to ensure that they don't go away while we're moving tasks about. This is done by linking cset->mg_preload_node on either the mgctx->preloaded_src_csets or mgctx->preloaded_dst_csets list. Using the same cset->mg_preload_node for both the src and dst lists was deemed okay as a cset can't be both the source and destination at the same time. Unfortunately, this overloading becomes problematic when multiple tasks are involved in a migration and some of them are identity noop migrations while others are actually moving across cgroups. For example, this can happen with the following sequence on cgroup1: #1> mkdir -p /sys/fs/cgroup/misc/a/b #2> echo $$ > /sys/fs/cgroup/misc/a/cgroup.procs #3> RUN_A_COMMAND_WHICH_CREATES_MULTIPLE_THREADS & #4> PID=$! #5> echo $PID > /sys/fs/cgroup/misc/a/b/tasks #6> echo $PID > /sys/fs/cgroup/misc/a/cgroup.procs the process including the group leader back into a. In this final migration, non-leader threads would be doing identity migration while the group leader is doing an actual one. After #3, let's say the whole process was in cset A, and that after #4, the leader moves to cset B. Then, during #6, the following happens: 1. cgroup_migrate_add_src() is called on B for the leader. 2. cgroup_migrate_add_src() is called on A for the other threads. 3. cgroup_migrate_prepare_dst() is called. It scans the src list. 4. It notices that B wants to migrate to A, so it tries to A to the dst list but realizes that its ->mg_preload_node is already busy. 5. and then it notices A wants to migrate to A as it's an identity migration, it culls it by list_del_init()'ing its ->mg_preload_node and putting references accordingly. 6. The rest of migration tak

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= f817de98513d060023be4fa1d061b29a6515273e < 05f7658210d1d331e8dd4cb6e7bbbe3df5f5ac2705f7658210d1d331e8dd4cb6e7bbbe3df5f5ac27
linuxlinux>= f817de98513d060023be4fa1d061b29a6515273e < cec2bbdcc14fbaa6b95ee15a7c423b05d97038becec2bbdcc14fbaa6b95ee15a7c423b05d97038be
linuxlinux>= f817de98513d060023be4fa1d061b29a6515273e < ad44e05f3e016bdcb1ad25af35ade5b5f41ccd68ad44e05f3e016bdcb1ad25af35ade5b5f41ccd68
linuxlinux>= f817de98513d060023be4fa1d061b29a6515273e < 7657e3958535d101a24ab4400f9b8062b9107cc47657e3958535d101a24ab4400f9b8062b9107cc4
linuxlinux>= f817de98513d060023be4fa1d061b29a6515273e < 54aee4e5ce8c21555286a6333e46c1713880cf9354aee4e5ce8c21555286a6333e46c1713880cf93
linuxlinux>= f817de98513d060023be4fa1d061b29a6515273e < 0e41774b564befa6d271e8d5086bf870d617a4e60e41774b564befa6d271e8d5086bf870d617a4e6
linuxlinux>= f817de98513d060023be4fa1d061b29a6515273e < 07fd5b6cdf3cc30bfde8fe0f644771688be0444707fd5b6cdf3cc30bfde8fe0f644771688be04447
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 3.16 < 4.14.2894.14.289
linuxlinux_kernel>= 4.15 < 4.19.2534.19.253
linuxlinux_kernel>= 4.20 < 5.4.2075.4.207
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.5 < 5.10.1325.10.132

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.