CVE-2022-48638: Linux Kernel

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: cgroup: cgroup_get_from_id() must check the looked-up kn is a directory cgroup has to be one kernfs dir, otherwise kernel panic is caused, especially cgroup id is provide from userspace.

Affected products

  • Linux Linux Kernel: from 5.14, before 5.15.72 (fixed in 5.15.72); from 5.16, before 5.19.12 (fixed in 5.19.12); version 6.0 only

Published 2024-04-28. Last modified 2026-06-17.