In the Linux kernel, the following vulnerability has been resolved:
cgroup: cgroupgetfrom_id() must check the looked-up kn is a directory
cgroup has to be one kernfs dir, otherwise kernel panic is caused, especially cgroup id is provide from userspace.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"60215029021057367357772528624181926835",
"181544605666602686540928215046549041799",
"102043200260881067534684472658622101660",
"237818250880552332106519413133442451965",
"250360623382268345357630143205740312462",
"177243088893359491458958860328470497007"
]
},
"target": {
"file": "kernel/cgroup/cgroup.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8484a356cee8ce3d6a8e6266ff99be326e9273ad",
"id": "CVE-2022-48638-27b73be8"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"60215029021057367357772528624181926835",
"181544605666602686540928215046549041799",
"102043200260881067534684472658622101660",
"237818250880552332106519413133442451965",
"250360623382268345357630143205740312462",
"177243088893359491458958860328470497007"
]
},
"target": {
"file": "kernel/cgroup/cgroup.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@df02452f3df069a59bc9e69c84435bf115cb6e37",
"id": "CVE-2022-48638-83a83fef"
},
{
"digest": {
"length": 313.0,
"function_hash": "193999508688183777311591323447088993183"
},
"target": {
"function": "cgroup_get_from_id",
"file": "kernel/cgroup/cgroup.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8484a356cee8ce3d6a8e6266ff99be326e9273ad",
"id": "CVE-2022-48638-8d8bff62"
},
{
"digest": {
"length": 313.0,
"function_hash": "193999508688183777311591323447088993183"
},
"target": {
"function": "cgroup_get_from_id",
"file": "kernel/cgroup/cgroup.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@df02452f3df069a59bc9e69c84435bf115cb6e37",
"id": "CVE-2022-48638-fdbe2b5c"
}
]