CVE-2022-48760 is a Linux kernel USB-core synchronization flaw that can leave processes indefinitely blocked in usb_kill_urb() on SMP systems. Insufficient memory ordering between concurrent usb_kill_urb() and __usb_hcd_giveback_urb() operations can cause a USB request block completion wake-up to be missed; equivalent store-buffering patterns also affect usb_poison_urb() and the failure path of usb_hcd_submit_urb().
The upstream fix adds full memory barriers through smp_mb__after_atomic() and is available in kernel versions 4.4.302, 4.9.300, 4.14.265, 4.19.228, 5.4.176, 5.10.96, 5.15.19, 5.16.5, and 5.17 or later. Red Hat rated the issue Low severity (CVSS 4.1) and released RHEL 8 kernel and kernel-rt updates in RHSA-2024:7000 and RHSA-2024:7001; RHEL 9 fixes remain deferred, while RHEL 6 and 7 are outside support scope.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt to remediate CVE-2022-48760.
The Linux kernel CVE team published CVE-2022-48760 for an SMP memory-ordering flaw in the USB core that can leave processes indefinitely waiting in usb_kill_urb(). The disclosure documented memory-barrier fixes, including smp_mb__after_atomic(), and identified fixed stable kernel versions from 4.4.302 through 5.17 and later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.