SB20251230264 - Improper locking in Linux kernel vhost driver
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-50851)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the DEFINE_IDA(), vhost_vdpa_remove_as(), vhost_vdpa_unlocked_ioctl(), vhost_vdpa_pa_unmap(), vhost_vdpa_va_unmap() and vhost_vdpa_unmap() functions in drivers/vhost/vdpa.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/26b7400c89b81e2f6de4f224ba1fdf06f293de31
- https://git.kernel.org/stable/c/8b258a31c2e8d4d4e42be70a7c6ca35a5afbff0d
- https://git.kernel.org/stable/c/e794070af224ade46db368271896b2685ff4f96b
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.19
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2