CVE-2025-22072
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/04/2025
Last modified:
03/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
spufs: fix gang directory lifetimes<br />
<br />
prior to "[POWERPC] spufs: Fix gang destroy leaks" we used to have<br />
a problem with gang lifetimes - creation of a gang returns opened<br />
gang directory, which normally gets removed when that gets closed,<br />
but if somebody has created a context belonging to that gang and<br />
kept it alive until the gang got closed, removal failed and we<br />
ended up with a leak.<br />
<br />
Unfortunately, it had been fixed the wrong way. Dentry of gang<br />
directory was no longer pinned, and rmdir on close was gone.<br />
One problem was that failure of open kept calling simple_rmdir()<br />
as cleanup, which meant an unbalanced dput(). Another bug was<br />
in the success case - gang creation incremented link count on<br />
root directory, but that was no longer undone when gang got<br />
destroyed.<br />
<br />
Fix consists of<br />
* reverting the commit in question<br />
* adding a counter to gang, protected by ->i_rwsem<br />
of gang directory inode.<br />
* having it set to 1 at creation time, dropped<br />
in both spufs_dir_close() and spufs_gang_close() and bumped<br />
in spufs_create_context(), provided that it&#39;s not 0.<br />
* using simple_recursive_removal() to take the gang<br />
directory out when counter reaches zero.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.23 (including) | 6.1.134 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.87 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.23 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.13.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.14 (including) | 6.14.2 (excluding) |
| cpe:2.3:o:linux:linux_kernel:2.6.22:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.22:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.22:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.22:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/029d8c711f5e5fe8cf63e8a4a1a140a06e224e45
- https://git.kernel.org/stable/c/324f280806aab28ef757aecc18df419676c10ef8
- https://git.kernel.org/stable/c/880e7b3da2e765c1f90c94c0539be039e96c7062
- https://git.kernel.org/stable/c/903733782f3ae28a2f7fe4dfb47c7fe3e079a528
- https://git.kernel.org/stable/c/c134deabf4784e155d360744d4a6a835b9de4dd4
- https://git.kernel.org/stable/c/fc646a6c6d14b5d581f162a7e32999f789e3a3ac
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html



