CVE-2022-48988: Linux Kernel
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: memcg: fix possible use-after-free in memcg_write_event_control() memcg_write_event_control() accesses the dentry->d_name of the specified control fd to route the write call. As a cgroup interface file can't be renamed, it's safe to access d_name as long as the specified file is a regular cgroup file. Also, as these cgroup interface files can't be removed before the directory, it's safe to access the parent too. Prior to 347c4a874710 ("memcg: remove cgroup_event->cft"), there was a call to __file_cft() which verified that the specified file is a regular cgroupfs file before further accesses. The cftype pointer returned from __file_cft() was no longer necessary and the commit inadvertently dropped the file type check with it allowing any file to slip through. With the invarients broken, the d_name and parent accesses can now race against renames and removals of arbitrary files and cause use-after-free's. Fix the bug by resurrecting the file type check in __file_cft(). Now that cgroupfs is implemented through kernfs, checking the file operations needs to go through a layer of indirection. Instead, let's check the superblock and dentry type.
Affected products
- Linux Linux Kernel: from 3.14, before 4.14.302 (fixed in 4.14.302); from 4.15, before 4.19.269 (fixed in 4.19.269); from 4.20, before 5.4.227 (fixed in 5.4.227); from 5.5, before 5.10.159 (fixed in 5.10.159); from 5.11, before 5.15.83 (fixed in 5.15.83); from 5.16, before 6.0.13 (fixed in 6.0.13); …
Published 2024-10-21. Last modified 2026-08-04.