CVE-2022-48921
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-48921 affects the Linux kernel's scheduler component, specifically in the reweightentity function. The vulnerability was discovered by Syzbot and was introduced by commit 4ef0c5c6b5ba. The issue involves a race condition between schedpostfork() and setpriority(PRIOPGRP) within a thread group that can lead to a null pointer dereference in the CFS (Completely Fair Scheduler) (NVD).

Technical details

The vulnerability occurs when a main process spawns new threads that call setpriority(PRIOPGRP, 0, -20). During thread creation, copyprocess() is invoked to add the new taskstruct and call schedpostfork(). A race condition exists where setpriority(PRIOPGRP) and setoneprio() might be called for a thread that is still being created by copyprocess(), before schedpostfork() execution. This leads to a null pointer dereference in reweightentity() when attempting to access an uninitialized run queue pointer. The vulnerability has a CVSS v3.1 Base Score of 4.7 MEDIUM (AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H) (NVD).

Impact

The vulnerability can result in a null pointer dereference, potentially causing a kernel crash and system denial of service when exploited (NVD).

Mitigation and workarounds

The issue has been fixed by removing the updateload parameter from the updateload param() function and modifying reweighttask() to only execute when the task flag doesn't have the TASKNEW flag set. The fix is implemented in kernel patch 13765de8148f71fa795e0a6607de37c49ea5915a (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management