IT

Tracker / CVE-2022-48671

CVE-2022-48671

Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() syzbot is hitting percpu_rwsem_assert_held(&cpu_hotplug_lock) warning at cpuset_attach() [1], for commit 4f7e7236435ca0ab ("cgroup: Fix threadgroup_rwsem <-> cpus_read_lock() deadlock") missed that cpuset_attach() is also called from cgroup_attach_task_all(). Add cpus_read_lock() like what cgroup_procs_write_start() does.

Affected products and versions

linux linux_kernel · 5.10.143 → 5.10.145
linux linux_kernel · 5.15.68 → 5.15.70
linux linux_kernel · 5.19.9 → 5.19.11
linux linux_kernel · 5.4.213 → 5.4.215

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References