perf: Fix perf_pending_task() UaF
Published Oct 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.25%
Description
Per syzbot it is possible for perf_pending_task() to run after the event is free()'d. There are two related but distinct cases:
- the task_work was already queued before destroying the event; - destroying the event itself queues the task_work.
The first cannot be solved using task_work_cancel() since perf_release() itself might be called from a task_work (____fput), which means the current->task_works list is already empty and task_work_cancel() won't be able to find the perf_pending_task() entry.
The simplest alternative is extending the perf_event lifetime to cover the task_work.
The second is just silly, queueing a task_work while you know the event is going away makes no sense and is easily avoided by re-arranging how the event is marked STATE_DEAD and ensuring it goes through STATE_OFF on the way down.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.15.77StatusaffectedConstraints<5.15.84
- Version 6.0.7StatusaffectedConstraints<6.0.14
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- < 5.15.84
- ≥ 5.16 · < 6.0.14
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-48950 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320683 Issue Tracking
- https://git.kernel.org/stable/c/517e6a301f34613bff24a8e35b5455884f2d83d8 Patch
- https://git.kernel.org/stable/c/78e1317a174edbfd1182599bf76c092a2877672c Patch
- https://git.kernel.org/stable/c/8bffa95ac19ff27c8261904f89d36c7fcf215d59 Patch
- https://lore.kernel.org/linux-cve-announce/2024102141-CVE-2022-48950-dc5f@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48950
- https://www.cve.org/CVERecord?id=CVE-2022-48950
Change history (0)
No recorded changes yet.