{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2022-48892","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-08-21T06:06:23.290Z","datePublished":"2024-08-21T06:10:24.407Z","dateUpdated":"2026-08-05T08:52:49.416Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:52:49.416Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/core: Fix use-after-free bug in dup_user_cpus_ptr()\n\nSince commit 07ec77a1d4e8 (\"sched: Allow task CPU affinity to be\nrestricted on asymmetric systems\"), the setting and clearing of\nuser_cpus_ptr are done under pi_lock for arm64 architecture. However,\ndup_user_cpus_ptr() accesses user_cpus_ptr without any lock\nprotection. Since sched_setaffinity() can be invoked from another\nprocess, the process being modified may be undergoing fork() at\nthe same time.  When racing with the clearing of user_cpus_ptr in\n__set_cpus_allowed_ptr_locked(), it can lead to user-after-free and\npossibly double-free in arm64 kernel.\n\nCommit 8f9ea86fdf99 (\"sched: Always preserve the user requested\ncpumask\") fixes this problem as user_cpus_ptr, once set, will never\nbe cleared in a task's lifetime. However, this bug was re-introduced\nin commit 851a723e45d1 (\"sched: Always clear user_cpus_ptr in\ndo_set_cpus_allowed()\") which allows the clearing of user_cpus_ptr in\ndo_set_cpus_allowed(). This time, it will affect all arches.\n\nFix this bug by always clearing the user_cpus_ptr of the newly\ncloned/forked task before the copying process starts and check the\nuser_cpus_ptr state of the source task under pi_lock.\n\nNote to stable, this patch won't be applicable to stable releases.\nJust copy the new dup_user_cpus_ptr() function over."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Reachable only via local syscalls (fork/clone racing with sched_setaffinity); there is no network or adjacent-packet path into dup_user_cpus_ptr().\nAC:L - The attacker controls both sides of the race (one thread/process forking while another same-UID thread repeatedly calls sched_setaffinity on the forking task), so success does not depend on conditions outside attacker control.\nPR:L - An unprivileged user can trigger both fork and sched_setaffinity on their own tasks via check_same_owner without CAP_SYS_NICE; user_cpus_ptr is also established by unprivileged execve on asymmetric arm64.\nUI:N - Exploitation requires no victim action; the attacker triggers fork and affinity changes entirely themselves.\nS:U - This is a standard kernel heap UAF/double-free enabling privilege escalation within the same kernel security authority, not a VM/IOMMU/sandbox boundary cross.\nC:H - Use-after-free of the kmalloc'd cpumask lets an attacker reclaim the object and obtain arbitrary kernel read primitives from the corrupted heap.\nI:H - The same UAF/double-free is exploitable for heap spraying and arbitrary write/control-flow hijack in the kernel, enabling integrity compromise and code execution.\nA:H - The race can NULL-dereference or free still-referenced memory, causing kernel oops/panic, and UAF crashes remain likely even when not fully exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/sched/core.c"],"versions":[{"version":"07ec77a1d4e82526e1588979fff2f024f8e96df2","lessThan":"b22faa21b6230d5eccd233e1b7e0026a5002b287","status":"affected","versionType":"git"},{"version":"07ec77a1d4e82526e1588979fff2f024f8e96df2","lessThan":"7b5cc7fd1789ea5dbb942c9f8207b076d365badc","status":"affected","versionType":"git"},{"version":"07ec77a1d4e82526e1588979fff2f024f8e96df2","lessThan":"87ca4f9efbd7cc649ff43b87970888f2812945b8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/sched/core.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.15.89","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.7","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.89"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b22faa21b6230d5eccd233e1b7e0026a5002b287"},{"url":"https://git.kernel.org/stable/c/7b5cc7fd1789ea5dbb942c9f8207b076d365badc"},{"url":"https://git.kernel.org/stable/c/87ca4f9efbd7cc649ff43b87970888f2812945b8"}],"title":"sched/core: Fix use-after-free bug in dup_user_cpus_ptr()","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2022-48892","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T16:04:18.997658Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-12T17:33:06.281Z"}}]}}