From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 548F519E999 for ; Wed, 26 Feb 2025 01:57:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740535079; cv=none; b=tD0eTrGhOQfuo4HxmdZNt7q37lxht4e035GzdnZW/aNMtb6Sow1J0Bh1yqlO371N+1KRWVhz8xgYE1UhP25Luwp2aTL48aL2wUKSGkG/GB0gQXEumgzJ0N1QU14eVcMqvJzMbVR/oaP7Ve1cikIn1EG4NIqg5mfIzHYvL26EOus= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1740535079; c=relaxed/simple; bh=HBqnnGos/ccc6ib0AdAbLLzO93jMVnXYxB8RAIETurg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=qoc55kTIdpom2ZlX9ZSVCAw6I3wZDez7i+S3jcUhLnqfqad0ab6sKvDQnCG9Ppet4jTnev9oMpf0X+MapvM9/zdH2w34mrYohXahTe/bixYB0fs6B9snrzO1nOBq0fzIGIrTHH1IGdjdDqlI9AlvfEwu7J4IRV0+FeVhX6NoDMg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=YL4KW5VP; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="YL4KW5VP" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 286BDC4CEDD; Wed, 26 Feb 2025 01:57:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1740535079; bh=HBqnnGos/ccc6ib0AdAbLLzO93jMVnXYxB8RAIETurg=; h=From:To:Cc:Subject:Date:Reply-to:From; b=YL4KW5VPLCjjrNO10t8GUjnlvYYaDiWFA/OFjxwLkWtyCwlOnPwYcrH6eQLACM4Ph vNmCIDTc2YnT/70ZacijtYCn70cvSDmRTZhGoL3sKKm6NdlehSIN39wAx5BALqv+kh luRUkP4fWW2iirlA13/uTEcPUOmN+BCXeuKtjI7Y= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2022-49080: mm/mempolicy: fix mpol_new leak in shared_policy_replace Date: Wed, 26 Feb 2025 02:54:45 +0100 Message-ID: <2025022656-CVE-2022-49080-5718@gregkh> X-Mailer: git-send-email 2.48.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=4146; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=HBqnnGos/ccc6ib0AdAbLLzO93jMVnXYxB8RAIETurg=; b=owGbwMvMwCRo6H6F97bub03G02pJDOn7SkyunJA/XM36fqPWz6yb05XXPdN6bxrzPczxXsuUW 9teVMu1dMSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEzD0Y5hcrvd31UjPq5MfI GZ7b5v6JE99xdALDfB+W/QLf7q5eqaKWvGutjdlx+bkC8wE= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: fix mpol_new leak in shared_policy_replace If mpol_new is allocated but not used in restart loop, mpol_new will be freed via mpol_put before returning to the caller. But refcnt is not initialized yet, so mpol_put could not do the right things and might leak the unused mpol_new. This would happen if mempolicy was updated on the shared shmem file while the sp->lock has been dropped during the memory allocation. This issue could be triggered easily with the below code snippet if there are many processes doing the below work at the same time: shmid = shmget((key_t)5566, 1024 * PAGE_SIZE, 0666|IPC_CREAT); shm = shmat(shmid, 0, 0); loop many times { mbind(shm, 1024 * PAGE_SIZE, MPOL_LOCAL, mask, maxnode, 0); mbind(shm + 128 * PAGE_SIZE, 128 * PAGE_SIZE, MPOL_DEFAULT, mask, maxnode, 0); } The Linux kernel CVE team has assigned CVE-2022-49080 to this issue. Affected and fixed versions =========================== Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 4.9.311 with commit 8510c2346d9e47a72b7f018a36ef0c39483e53d6 Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 4.14.276 with commit 5e16dc5378abd749a836daa9ee4ab2c8d2668999 Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 4.19.238 with commit 39a32f3c06f6d68a530bf9612afa19f50f12e93d Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 5.4.189 with commit 25f506273b6ae806fd46bfcb6fdaa5b9ec81a05b Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 5.10.111 with commit f7e183b0a7136b6dc9c7b9b2a85a608a8feba894 Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 5.15.34 with commit 198932a14aeb19a15cf19e51e151d023bc4cd648 Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 5.16.20 with commit 6e00309ac716fa8225f0cbde2cd9c24f0e74ee21 Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 5.17.3 with commit fe39ac59dbbf893b73b24e3184161d0bd06d6651 Issue introduced in 3.8 with commit 42288fe366c4f1ce7522bc9f27d0bc2a81c55264 and fixed in 5.18 with commit 4ad099559b00ac01c3726e5c95dc3108ef47d03e Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2022-49080 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: mm/mempolicy.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/8510c2346d9e47a72b7f018a36ef0c39483e53d6 https://git.kernel.org/stable/c/5e16dc5378abd749a836daa9ee4ab2c8d2668999 https://git.kernel.org/stable/c/39a32f3c06f6d68a530bf9612afa19f50f12e93d https://git.kernel.org/stable/c/25f506273b6ae806fd46bfcb6fdaa5b9ec81a05b https://git.kernel.org/stable/c/f7e183b0a7136b6dc9c7b9b2a85a608a8feba894 https://git.kernel.org/stable/c/198932a14aeb19a15cf19e51e151d023bc4cd648 https://git.kernel.org/stable/c/6e00309ac716fa8225f0cbde2cd9c24f0e74ee21 https://git.kernel.org/stable/c/fe39ac59dbbf893b73b24e3184161d0bd06d6651 https://git.kernel.org/stable/c/4ad099559b00ac01c3726e5c95dc3108ef47d03e