CVE-2022-48939

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/08/2024
Last modified:
22/08/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf: Add schedule points in batch ops<br /> <br /> syzbot reported various soft lockups caused by bpf batch operations.<br /> <br /> INFO: task kworker/1:1:27 blocked for more than 140 seconds.<br /> INFO: task hung in rcu_barrier<br /> <br /> Nothing prevents batch ops to process huge amount of data,<br /> we need to add schedule points in them.<br /> <br /> Note that maybe_wait_bpf_programs(map) calls from<br /> generic_map_delete_batch() can be factorized by moving<br /> the call after the loop.<br /> <br /> This will be done later in -next tree once we get this fix merged,<br /> unless there is strong opinion doing this optimization sooner.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.6 (including) 5.10.103 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.26 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.16.12 (excluding)