CVE-2022-48944: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: sched: Fix yet more sched_fork() races Where commit 4ef0c5c6b5ba ("kernel/sched: Fix sched_fork() access an invalid sched_task_group") fixed a fork race vs cgroup, it opened up a race vs syscalls by not placing the task on the runqueue before it gets exposed through the pidhash. Commit 13765de8148f ("sched/fair: Fix fault in reweight_entity") is trying to fix a single instance of this, instead fix the whole class of issues, effectively reverting this commit.
Affected products
- Linux Linux Kernel: from 5.15.3, before 5.15.27 (fixed in 5.15.27); from 5.16, before 5.16.13 (fixed in 5.16.13); version 5.10.80 only; version 5.14.19 only
Published 2024-08-30. Last modified 2026-06-17.