Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has to be one kernfs dir, otherwise kernel panic is caused, especially cgroup id is provide from userspace.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.14, < 5.15.72 |
References
- https://git.kernel.org/stable/c/1e9571887f97b17cf3ffe9aa4da89090ea60988bPatch
- https://git.kernel.org/stable/c/8484a356cee8ce3d6a8e6266ff99be326e9273adPatch
- https://git.kernel.org/stable/c/df02452f3df069a59bc9e69c84435bf115cb6e37Patch
- https://git.kernel.org/stable/c/1e9571887f97b17cf3ffe9aa4da89090ea60988bPatch
- https://git.kernel.org/stable/c/8484a356cee8ce3d6a8e6266ff99be326e9273adPatch
- https://git.kernel.org/stable/c/df02452f3df069a59bc9e69c84435bf115cb6e37Patch
FAQ
What is CVE-2022-48638?
CVE-2022-48638 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has to be one kernfs dir, otherwise kernel panic is...
How severe is CVE-2022-48638?
CVE-2022-48638 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48638?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.