Resource exhaustion in Linux kernel - CVE-2022-0480
Published: March 13, 2024
Vulnerability identifier: #VU87505
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0480
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memcg does not properly control consumption of internal resources within the filelock_init() function in fs/locks.c. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Linux kernel
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel-rt (Red Hat package)
kernel (Red Hat package)
Virtualization Management Interface
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel-rt (Red Hat package)
kernel (Red Hat package)
Virtualization Management Interface
How to mitigate CVE-2022-0480
Install updates from vendor's website.
Red Hat OpenShift Container Platform - addressed in versions 4.13.38, 4.14.18, 4.15.5
Virtualization Management Interface - update to FW1060.12
kernel-rt (Red Hat package) - addressed in versions 5.14.0-70.93.1.rt21.165.el9_0, 5.14.0-284.57.1.rt14.342.el9_2
kernel (Red Hat package) - addressed in versions 5.14.0-70.93.2.el9_0, 5.14.0-284.57.1.el9_2, 5.14.0-427.13.1.el9_4
Virtualization Management Interface - update to FW1060.12
kernel-rt (Red Hat package) - addressed in versions 5.14.0-70.93.1.rt21.165.el9_0, 5.14.0-284.57.1.rt14.342.el9_2
kernel (Red Hat package) - addressed in versions 5.14.0-70.93.2.el9_0, 5.14.0-284.57.1.el9_2, 5.14.0-427.13.1.el9_4
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=2049700
- https://github.com/kata-containers/kata-containers/issues/3373
- https://access.redhat.com/security/cve/CVE-2022-0480
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0f12156dff2862ac54235fc72703f18770769042
- https://ubuntu.com/security/CVE-2022-0480
- https://lore.kernel.org/linux-mm/20210902215519.AWcuVc3li%25akpm%40linux-foundation.org/
Related Security Bulletins
- Local denial of service in Linux kernel memcg
- Red Hat Enterprise Linux 9.0 Extended Update Support update for kernel
- Red Hat Enterprise Linux 9.2 Extended Update Support update for kernel-rt
- Red Hat Enterprise Linux 9.2 Extended Update Support update for kernel
- Red Hat Enterprise Linux 9.0 Extended Update Support update for kernel-rt
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Red Hat Enterprise Linux 9 update for kernel
- Multiple vulnerabilities in IBM Virtualization Management Interface