CVE-2022-50889

Description

A use-after-free vulnerability was found in the Linux kernel's device mapper integrity subsystem. When dm_resume() and dm_destroy() execute concurrently, a timer may fire and access freed memory because dm_integrity_dtr() did not properly cancel the timer before freeing resources. The fix adds an additional timer cancellation in the destructor path.

Statement

This flaw requires a race condition between dm_resume() and dm_destroy() operations on a dm-integrity device. While use-after-free bugs can have serious consequences, the narrow timing window and requirement for privileged device-mapper operations significantly limit exploitability in practice.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.5N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredLowN/AN/A
User InteractionNoneN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityNoneN/AN/A
Integrity ImpactNoneN/AN/A
Availability ImpactHighN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Integrity,Other

Technical Impact: Alter Execution Logic; Unexpected State

The main problem is that -- if a lock is overcome -- data could be altered in a bad state.

Frequently Asked Questions

Want to get errata notifications? Sign up here.