CVE-2022-49362
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-49362 is a vulnerability affecting the Linux kernel that has been addressed. It involves the NFS (Network File System) daemon, specifically the function nfsd_file_put(). In certain circumstances, this function can free memory allocated to the nfsd_file_struct object before it is fully utilized. Consequently, attempting to dereference the pointer to this object immediately after the function call may result in a use-after-free condition, potentially leading to arbitrary code execution or denial-of-service attacks. To mitigate this issue, the Linux kernel developers have implemented measures to prevent dereferencing the nfsd_file_struct pointer before ensuring its validity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX