CVE-2022-48638
published 2024-04-28CVE-2022-48638: In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has to be…
PriorityP421medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
cgroup has to be one kernfs dir, otherwise kernel panic is caused,
especially cgroup id is provide from userspace.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 6b658c4863c15936872a93c9ee879043bf6393c9 < 8484a356cee8ce3d6a8e6266ff99be326e9273ad | 8484a356cee8ce3d6a8e6266ff99be326e9273ad |
| linux | linux | >= 6b658c4863c15936872a93c9ee879043bf6393c9 < 1e9571887f97b17cf3ffe9aa4da89090ea60988b | 1e9571887f97b17cf3ffe9aa4da89090ea60988b |
| linux | linux | >= 6b658c4863c15936872a93c9ee879043bf6393c9 < df02452f3df069a59bc9e69c84435bf115cb6e37 | df02452f3df069a59bc9e69c84435bf115cb6e37 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 5.14 < 5.15.72 | 5.15.72 |
| linux | linux_kernel | >= 5.16 < 5.19.12 | 5.19.12 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ggqq-32pw-pm22: In the Linux kernel, the following vulnerability has been resolved:
cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
cgroup h
ghsa_unreviewed·2024-04-28
CVE-2022-48638 [MEDIUM] GHSA-ggqq-32pw-pm22: In the Linux kernel, the following vulnerability has been resolved:
cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
cgroup h
In the Linux kernel, the following vulnerability has been resolved:
cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
cgroup has to be one kernfs dir, otherwise kernel panic is caused,
especially cgroup id is provide from userspace.
OSV
CVE-2022-48638: In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has
osv·2024-04-28·CVSS 5.3
CVE-2022-48638 [MEDIUM] CVE-2022-48638: In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has
In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has to be one kernfs dir, otherwise kernel panic is caused, especially cgroup id is provide from userspace.
Red Hat
kernel: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
vendor_redhat·2024-04-28·CVSS 5.3
CVE-2022-48638 [MEDIUM] CWE-588 kernel: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
kernel: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
In the Linux kernel, the following vulnerability has been resolved:
cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
cgroup has to be one kernfs dir, otherwise kernel panic is caused,
especially cgroup id is provide from userspace.
A flaw was found in the Linux kernel in which certain cgroup configurations could cause a kernel panic, resulting in a Denial of Service.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel (Red
Debian
CVE-2022-48638: linux - In the Linux kernel, the following vulnerability has been resolved: cgroup: cgr...
vendor_debian·2022·CVSS 5.3
CVE-2022-48638 [MEDIUM] CVE-2022-48638: linux - In the Linux kernel, the following vulnerability has been resolved: cgroup: cgr...
In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has to be one kernfs dir, otherwise kernel panic is caused, especially cgroup id is provide from userspace.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1e9571887f97b17cf3ffe9aa4da89090ea60988bhttps://git.kernel.org/stable/c/8484a356cee8ce3d6a8e6266ff99be326e9273adhttps://git.kernel.org/stable/c/df02452f3df069a59bc9e69c84435bf115cb6e37https://git.kernel.org/stable/c/1e9571887f97b17cf3ffe9aa4da89090ea60988bhttps://git.kernel.org/stable/c/8484a356cee8ce3d6a8e6266ff99be326e9273adhttps://git.kernel.org/stable/c/df02452f3df069a59bc9e69c84435bf115cb6e37
2024-04-28
Published