CVE-2022-49464

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 26, 2025
Updated: Feb 27, 2025
CWE ID 416

Summary

CVE-2022-49464 is a vulnerability in the Linux kernel's EROFS file system. The issue involves a use-after-free error in the 'z_erofs_shifted_transform' function. KASAN reports indicate that this issue can lead to a buffer copy overflow in the ztailpacking feature. The root cause is that the tail pcluster may no longer be a complete filesystem block when ztailpacking is used. Consequently, the second part of an uncompressed tail pcluster may not be correctly referenced, leading to potential memory corruption.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share