#VU99009 Improper locking in Linux kernel


Vulnerability identifier: #VU99009

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-49033

CWE-ID: CWE-667

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the btrfs_qgroup_inherit() function in fs/btrfs/qgroup.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/89840b12c8fad7200eb6478525c13261512c01be
http://git.kernel.org/stable/c/3c98e91be6aea4c7acf09da6eb0c107ea9186bb5
http://git.kernel.org/stable/c/f4b930a1602b05e77fee31f9616599b25e910a86
http://git.kernel.org/stable/c/8eb912af525042a7365295eb62f6d5270c2a6462
http://git.kernel.org/stable/c/01d7c41eac9129fba80d8aed0060caab4a7dbe09
http://git.kernel.org/stable/c/044da1a371a0da579e805e89c96865f62d8f6f69
http://git.kernel.org/stable/c/588ae4fdd8b11788a797776b10d6c44ae12bc133
http://git.kernel.org/stable/c/f7e942b5bb35d8e3af54053d19a6bf04143a3955


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability