CVE-2022-49892: ftrace: Fix use-after-free for dynamic ftrace_ops

Published May 1, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ftrace: Fix use-after-free for dynamic ftraceops

KASAN reported a use-after-free with ftrace ops [1]. It was found from vmcore that perf had registered two ops with the same content successively, both dynamic. After unregistering the second ops, a use-after-free occurred.

In ftraceshutdown(), when the second ops is unregistered, the FTRACEUPDATECALLS command is not set because there is another enabled ops with the same content. Also, both ops are dynamic and the ftrace callback function is ftraceopslistfunc, so the FTRACEUPDATETRACEFUNC command will not be set. Eventually the value of 'command' will be 0 and ftraceshutdown() will skip the rcu synchronization.

However, ftrace may be activated. When the ops is released, another CPU may be accessing the ops. Add the missing synchronization to fix this problem.

[1] BUG: KASAN: use-after-free in ftraceopslistfunc kernel/trace/ftrace.c:7020 [inline] BUG: KASAN: use-after-free in ftraceopslistfunc+0x2b0/0x31c kernel/trace/ftrace.c:7049 Read of size 8 at addr ffff56551965bbc8 by task syz-executor.2/14468

CPU: 1 PID: 14468 Comm: syz-executor.2 Not tainted 5.10.0 #7 Hardware name: linux,dummy-virt (DT) Call trace: dumpbacktrace+0x0/0x40c arch/arm64/kernel/stacktrace.c:132 showstack+0x30/0x40 arch/arm64/kernel/stacktrace.c:196 dumpstack lib/dumpstack.c:77 [inline] dumpstack+0x1b4/0x248 lib/dumpstack.c:118 printaddressdescription.constprop.0+0x28/0x48c mm/kasan/report.c:387 kasanreport mm/kasan/report.c:547 [inline] kasanreport+0x118/0x210 mm/kasan/report.c:564 checkmemoryregioninline mm/kasan/generic.c:187 [inline] asanload8+0x98/0xc0 mm/kasan/generic.c:253 ftraceopslistfunc kernel/trace/ftrace.c:7020 [inline] ftraceopslistfunc+0x2b0/0x31c kernel/trace/ftrace.c:7049 ftracegraphcall+0x0/0x4 mightsleep+0x8/0x100 include/linux/perfevent.h:1170 mightfault mm/memory.c:5183 [inline] mightfault+0x58/0x70 mm/memory.c:5171 dostrncpyfromuser lib/strncpyfromuser.c:41 [inline] strncpyfromuser+0x1f4/0x4b0 lib/strncpyfromuser.c:139 getnameflags+0xb0/0x31c fs/namei.c:149 getname+0x2c/0x40 fs/namei.c:209 [...]

Allocated by task 14445: kasansavestack+0x24/0x50 mm/kasan/common.c:48 kasansettrack mm/kasan/common.c:56 [inline] kasankmalloc mm/kasan/common.c:479 [inline] kasankmalloc.constprop.0+0x110/0x13c mm/kasan/common.c:449 kasankmalloc+0xc/0x14 mm/kasan/common.c:493 kmemcachealloctrace+0x440/0x924 mm/slub.c:2950 kmalloc include/linux/slab.h:563 [inline] kzalloc include/linux/slab.h:675 [inline] perfeventalloc.part.0+0xb4/0x1350 kernel/events/core.c:11230 perfeventalloc kernel/events/core.c:11733 [inline] dosysperfeventopen kernel/events/core.c:11831 [inline] sesysperfeventopen+0x550/0x15f4 kernel/events/core.c:11723 arm64sysperfeventopen+0x6c/0x80 kernel/events/core.c:11723 [...]

Freed by task 14445: kasansavestack+0x24/0x50 mm/kasan/common.c:48 kasansettrack+0x24/0x34 mm/kasan/common.c:56 kasansetfreeinfo+0x20/0x40 mm/kasan/generic.c:358 kasanslabfree.part.0+0x11c/0x1b0 mm/kasan/common.c:437 kasanslabfree mm/kasan/common.c:445 [inline] kasanslabfree+0x2c/0x40 mm/kasan/common.c:446 slabfreehook mm/slub.c:1569 [inline] slabfreefreelisthook mm/slub.c:1608 [inline] slabfree mm/slub.c:3179 [inline] kfree+0x12c/0xc10 mm/slub.c:4176 perfeventalloc.part.0+0xa0c/0x1350 kernel/events/core.c:11434 perfeventalloc kernel/events/core.c:11733 [inline] dosysperfeventopen kernel/events/core.c:11831 [inline] sesysperfeventopen+0x550/0x15f4 kernel/events/core.c:11723 [...]

Affected Software

10 affected components
Linux Linux kernel>=4.1.45<4.2
Linux Linux kernel>=4.4.89<4.5
Linux Linux kernel>=4.9.52<4.10
Linux Linux kernel>=4.13.4<5.10.154
Linux Linux kernel>=5.11<5.15.78
Linux Linux kernel>=5.16<6.0.8
Linux Linux kernel=6.1-rc1
Linux Linux kernel=6.1-rc2
Linux Linux kernel=6.1-rc3
Linux Kernel

Event History

May 1, 2025
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-49892?

CVE-2022-49892 is classified as a critical vulnerability due to its potential for exploitation via a use-after-free condition in the Linux kernel.

2

How do I fix CVE-2022-49892?

To fix CVE-2022-49892, upgrade to the patched version of the Linux kernel that addresses the use-after-free vulnerability in ftrace.

3

What systems are affected by CVE-2022-49892?

CVE-2022-49892 affects the Linux kernel versions that utilize the ftrace features and have dynamic ftrace_ops registered.

4

What are the potential impacts of CVE-2022-49892?

The potential impacts of CVE-2022-49892 include system crashes, unexpected behavior, and possible code execution due to memory corruption.

5

Is CVE-2022-49892 being actively exploited?

As of now, there are no widely reported active exploits for CVE-2022-49892, but it is recommended to apply fixes promptly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203