NONE · 0

CVE-2022-50855

In the Linux kernel, the following vulnerability has been resolved: bpf: prevent leak of lsm program after failed attach In [0], we added the ability to bpf_prog_attach LSM programs to cgroups, but ...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: bpf: prevent leak of lsm program after failed attach In [0], we added the ability to bpf_prog_attach LSM programs to cgroups, but in our validation to make sure the prog is meant to be attached to BPF_LSM_CGROUP, we return too early if the check fails. This results in lack of decrementing prog's refcnt (through bpf_prog_put) leaving the LSM program alive past the point of the expected lifecycle. This fix allows for the decrement to take place. [0] https://lore.kernel.org/all/[email protected]/

References

FAQ

What is CVE-2022-50855?

CVE-2022-50855 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: bpf: prevent leak of lsm program after failed attach In [0], we added the ability to bpf_prog_attach LSM programs to cgroups, but ...

How severe is CVE-2022-50855?

CVSS scoring is not yet available for CVE-2022-50855. Check NVD for updates.

Is there a patch for CVE-2022-50855?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.