CVE-2022-48671: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() syzbot is hitting percpu_rwsem_assert_held(&cpu_hotplug_lock) warning at cpuset_attach() [1], for commit 4f7e7236435ca0ab ("cgroup: Fix threadgroup_rwsem <-> cpus_read_lock() deadlock") missed that cpuset_attach() is also called from cgroup_attach_task_all(). Add cpus_read_lock() like what cgroup_procs_write_start() does.

Affected products

  • Linux Linux Kernel: from 5.4.213, before 5.4.215 (fixed in 5.4.215); from 5.10.143, before 5.10.145 (fixed in 5.10.145); after 5.15.68, before 5.15.70 (fixed in 5.15.70); from 5.19.9, before 5.19.11 (fixed in 5.19.11)

Published 2024-05-03. Last modified 2026-06-17.