cbcvebase.
CVE-2022-48638
published 2024-04-28

CVE-2022-48638: In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has to be…

PriorityP421medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has to be one kernfs dir, otherwise kernel panic is caused, especially cgroup id is provide from userspace.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 6b658c4863c15936872a93c9ee879043bf6393c9 < 8484a356cee8ce3d6a8e6266ff99be326e9273ad8484a356cee8ce3d6a8e6266ff99be326e9273ad
linuxlinux>= 6b658c4863c15936872a93c9ee879043bf6393c9 < 1e9571887f97b17cf3ffe9aa4da89090ea60988b1e9571887f97b17cf3ffe9aa4da89090ea60988b
linuxlinux>= 6b658c4863c15936872a93c9ee879043bf6393c9 < df02452f3df069a59bc9e69c84435bf115cb6e37df02452f3df069a59bc9e69c84435bf115cb6e37
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 5.14 < 5.15.725.15.72
linuxlinux_kernel>= 5.16 < 5.19.125.19.12

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.