CVE-2022-48671 - CVE House
Back to Database
Status published Unknown CVE-2022-48671

cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all()

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() syzbot is hitting percpu_rwsem_assert_held(&cpu_hotplug_lock) warning at cpuset_attach() [1], for commit 4f7e7236435ca0ab ("cgroup: Fix threadgroup_rwsem <-> cpus_read_lock() deadlock") missed that cpuset_attach() is also called from cgroup_attach_task_all(). Add cpus_read_lock() like what cgroup_procs_write_start() does.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-48671

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
e446300968c6bd25d9cd6c33b9600780a39b3975, 59c6902a96b4439e07c25ef86a4593bea5481c3b, dee1e2b18cf5426eed985512ccc6636ec69dbdd6, 3bf4bf54069f9b62a54988e5d085023c17a66c90, c0deb027c99c099aa6b831e326bfba802b25e774, 4f7e7236435ca0abe005c674ebd6892c6e83aeb3, 5.4.213, 5.10.143, 5.15.68, 5.19.9

Timeline

Official Publish: May 3rd, 2024
Last Modified: May 11th, 2026
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.