ACK: [SRU][J][PATCH 0/1] CVE-2022-49651
Andrei Gherzan
andrei.gherzan at canonical.com
Fri Sep 11 09:42:16 UTC 2026
On 26/09/09 02:14AM, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2022-49651
>
> [ Impact ]
>
> In the Linux kernel, the following vulnerability has been resolved:
>
> srcu: Tighten cleanup_srcu_struct() GP checks
>
> Currently, cleanup_srcu_struct() checks for a grace period in progress, but it
> does not check for a grace period that has not yet started but which might
> start at any time. Such a situation could result in a use-after-free bug, so
> this commit adds a check for a grace period that is needed but not yet started
> to cleanup_srcu_struct().
>
> [ Fix ]
>
> jammy/linux: clean cherry-pick of 8ed00760203d
>
> [ Test Plan ]
>
> Build and boot tested.
>
> [ Where Problems Could Occur ]
>
> This change touches the SRCU (Sleepable RCU) teardown path in the core
> kernel, so it is architecture- and hardware-independent and affects any
> system running jammy/linux. A bad fix could add a false-positive warning or
> stall during cleanup_srcu_struct(), which would primarily impact kernel
> subsystems and loadable modules that dynamically create and destroy SRCU
> structures (for example when modules are unloaded). Workloads that never
> tear down SRCU structures at runtime, and userspace applications generally,
> are not affected.
>
> [ Other Info ]
>
> Kybele flow-v11-21-g0f091652. Reference: 7095cf46/v1
Acked-by: Andrei Gherzan <andrei.gherzan at canonical.com>
--
Andrei Gherzan
gpg: rsa4096/D4D94F67AD0E9640
More information about the kernel-team
mailing list