#VU104656 Improper locking in Linux kernel - CVE-2022-49446
Published: February 26, 2025 / Updated: May 11, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the capability_show(), activate_show(), activate_store() and nvdimm_bus_firmware_visible() functions in drivers/nvdimm/core.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/2f97ebc58d5fc83ca1528cd553fa725472ab3ca8
- https://git.kernel.org/stable/c/2fd853fdb40afc052de338693df1372f2ead7be7
- https://git.kernel.org/stable/c/641649f31e20df630310f5c22f26c071acc676d4
- https://git.kernel.org/stable/c/ceb924ee16b2c8e48dcac3d9ad6be01c40b5a228
- https://git.kernel.org/stable/c/e6829d1bd3c4b58296ee9e412f7ed4d6cb390192
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.121
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.46
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19