CVE-2022-49127 Information

Description

In the Linux kernel the following vulnerability has been resolved:

ref_tracker: implement use-after-free detection

Whenever ref_tracker_dir_init() is called mark the struct ref_tracker_dir as dead.

Test the dead status from ref_tracker_alloc() and ref_tracker_free()

This should detect buggy dev_put()/dev_hold() happening too late in netdevice dismantle process.

Reference

https://git.kernel.org/stable/c/3743c9de303fa36c2e2ca2522ab280c52bcafbd2 https://git.kernel.org/stable/c/e3ececfe668facd87d920b608349a32607060e66

Share on: