CVE-2022-49412
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-49412 is a vulnerability affecting the Linux kernel's bfq (Budget Fair Queuing) scheduler. The issue arises when two bfqqs (bfq queues) with different parents are merged, causing potential use-after-free issues. This can occur when the parent of one bfqq changes between the merging decision and the actual merging process, leading to unexpected behavior such as memory corruption and crashes. The vulnerability can result in KASAN (Kernel Address Sanitizer) reports of use-after-free errors and can affect various Linux distributions and versions. The issue has been addressed by ensuring that the parents of the queues being merged are the same during the merging process.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX