CVE-2022-49349
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-49349 is a use-after-free vulnerability in the ext4 file system driver of the Linux kernel. The issue is caused by a failure to properly check directory entries in 'ext4_get_first_dir_block'. An attacker can exploit this vulnerability by manipulating directory entries to gain unauthorized access or cause a denial-of-service condition. The affected system may display a kernel message indicating a bad access detected and may become unresponsive. To mitigate this issue, it is recommended to check directory entries in 'ext4_get_first_dir_block' and return an error code if the file system is corrupted.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX