CVE-2022-48939
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/08/2024
Last modified:
22/08/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
bpf: Add schedule points in batch ops<br />
<br />
syzbot reported various soft lockups caused by bpf batch operations.<br />
<br />
INFO: task kworker/1:1:27 blocked for more than 140 seconds.<br />
INFO: task hung in rcu_barrier<br />
<br />
Nothing prevents batch ops to process huge amount of data,<br />
we need to add schedule points in them.<br />
<br />
Note that maybe_wait_bpf_programs(map) calls from<br />
generic_map_delete_batch() can be factorized by moving<br />
the call after the loop.<br />
<br />
This will be done later in -next tree once we get this fix merged,<br />
unless there is strong opinion doing this optimization sooner.
Impact
Base Score 3.x
3.30
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.6 (including) | 5.10.103 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.26 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.16.12 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



