In the Linux kernel, the following vulnerability has been resolved:
cgroup/cpuset: Fix wrong check in update_parent_subparts_cpumask()
It was found that the check to see if a partition could use up all the cpus from the parent cpuset in update_parent_subparts_cpumask() was incorrect. As a result, it is possible to leave parent with no effective cpu left even if there are tasks in the parent cpuset. This can lead to system panic as reported in [1].
Fix this probem by updating the check to fail the enabling the partition if parent's effective_cpus is a subset of the child's cpus_allowed.
Also record the error code when an error happens in update_prstate() and add a test case where parent partition and child have the same cpu list and parent has task. Enabling partition in the child will fail in this case.
[1] https://www.spinics.net/lists/cgroups/msg36254.html
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade python3-perfUpgrade kernel-toolsUpgrade kernel-debuginfo-common-aarch64Upgrade bpftoolUpgrade kernel-libbpf-develUpgrade kernel-tools-develUpgrade perfUpgrade kernel-libbpf-staticUpgrade kernelUpgrade bpftool-debuginfoUpgrade kernel-debuginfoUpgrade kernel-libbpfUpgrade kernel-tools-debuginfoUpgrade kernel-livepatch-6.1.12-17.42Upgrade kernel-develUpgrade kernel-debuginfo-common-x86_64Upgrade perf-debuginfoUpgrade kernel-headersUpgrade python3-perf-debuginfo | Jun 11, 2025 | Mar 27, 2025 |
| Debian | — | Upgrade linux | Mar 31, 2025 | Mar 27, 2025 |
| Redhat_linux | — | No solution existsUpgrade kernel | Jul 9, 2025 | Mar 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub