SB20250422125 - Improper locking in Linux kernel fs
Published: April 22, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2025-22029)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the begin_new_exec(), free_bprm(), check_unsafe_exec(), bprm_execve() and sched_mm_cid_after_execve() functions in fs/exec.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/753a620a7f8e134b444f89fe90873234e894e21a
- https://git.kernel.org/stable/c/a6b5070721503fb6021ebed51c925ffc66b1c5ab
- https://git.kernel.org/stable/c/af7bb0d2ca459f15cb5ca604dab5d9af103643f0
- https://git.kernel.org/stable/c/b519f2e5800fe2391b7545ba6889df795828e885
- https://git.kernel.org/stable/c/e2d8e7bd3314485e0b3b08380c659b3d1d67ed6a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.23