CVE-2022-48944 Information

Description

In the Linux kernel the following vulnerability has been resolved:

sched: Fix yet more sched_fork() races

Where commit 4ef0c5c6b5ba (\kernel/sched: Fix sched_fork() access an invalid sched_task_group) fixed a fork race vs cgroup it opened up a race vs syscalls by not placing the task on the runqueue before it gets exposed through the pidhash.

Commit 13765de8148f (\sched/fair: Fix fault in reweight_entity) is trying to fix a single instance of this instead fix the whole class of issues effectively reverting this commit.

Reference

https://git.kernel.org/stable/c/3411613611a5cddf7e80908010dc87cb527dd13b https://git.kernel.org/stable/c/c65cfd89cef669d90c59f3bf150af6458137a04f https://git.kernel.org/stable/c/b1e8206582f9d680cff7d04828708c8b6ab32957

Share on: