In the Linux kernel, the following vulnerability has been resolved:
cgroup/cpuset: Fix wrong check in update_parent_subparts_cpumask()
It was found that the check to see if a partition could use up all the cpus from the parent cpuset in update_parent_subparts_cpumask() was incorrect. As a result, it is possible to leave parent with no effective cpu left even if there are tasks in the parent cpuset. This can lead to system panic as reported in [1].
Fix this probem by updating the check to fail the enabling the partition if parent's effective_cpus is a subset of the child's cpus_allowed.
Also record the error code when an error happens in update_prstate() and add a test case where parent partition and child have the same cpu list and parent has task. Enabling partition in the child will fail in this case.
[1] https://www.spinics.net/lists/cgroups/msg36254.html
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade perf-debuginfoUpgrade kernel-develUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernel-libbpfUpgrade kernel-livepatch-6.1.12-17.42Upgrade python3-perf-debuginfoUpgrade kernel-headersUpgrade kernel-toolsUpgrade kernel-libbpf-develUpgrade perfUpgrade bpftoolUpgrade kernel-debuginfo-common-aarch64Upgrade python3-perfUpgrade kernelUpgrade kernel-tools-develUpgrade kernel-libbpf-static | Jun 11, 2025 | Mar 27, 2025 |
| Debian | — | Upgrade linux | Mar 31, 2025 | Mar 27, 2025 |
| Redhat_linux | — | Upgrade kernelNo solution exists | Jul 9, 2025 | Mar 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub