SB2025091879 - Improper locking in Linux kernel dlm
Published: September 18, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-50373)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the dlm_lowcomms_new_msg() and dlm_lowcomms_commit_msg() functions in fs/dlm/lowcomms.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/27d3e646dd83bafd7094890462eebfce3ac31e4a
- https://git.kernel.org/stable/c/30ea3257e8766027c4d8d609dcbd256ff9a76073
- https://git.kernel.org/stable/c/de7fdff754bb4d01e38e19964c309b6df6a79472
- https://git.kernel.org/stable/c/eb97e60a9eae632ff9104a580dbc4fdc58dc23cb
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.17