CVE-2022-48944
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/08/2024
Last modified:
03/09/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
sched: Fix yet more sched_fork() races<br />
<br />
Where commit 4ef0c5c6b5ba ("kernel/sched: Fix sched_fork() access an<br />
invalid sched_task_group") fixed a fork race vs cgroup, it opened up a<br />
race vs syscalls by not placing the task on the runqueue before it<br />
gets exposed through the pidhash.<br />
<br />
Commit 13765de8148f ("sched/fair: Fix fault in reweight_entity") is<br />
trying to fix a single instance of this, instead fix the whole class<br />
of issues, effectively reverting this commit.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.15.3 (including) | 5.15.27 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.16.13 (excluding) |
| cpe:2.3:o:linux:linux_kernel:5.10.80:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.14.19:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



