CVE-2022-49464
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 26, 2025
Updated: Feb 27, 2025
CWE ID 416
Summary
CVE-2022-49464 is a vulnerability in the Linux kernel's EROFS file system. The issue involves a use-after-free error in the 'z_erofs_shifted_transform' function. KASAN reports indicate that this issue can lead to a buffer copy overflow in the ztailpacking feature. The root cause is that the tail pcluster may no longer be a complete filesystem block when ztailpacking is used. Consequently, the second part of an uncompressed tail pcluster may not be correctly referenced, leading to potential memory corruption.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Linux Kernel
Affected Vendors
- LINUX