CVE-2022-49550
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2022-49550 is a vulnerability affecting the Linux kernel's NTFS3 filesystem. The issue stems from the absence of the 'invalidate_folio' method in the ntfs3 filesystem, leading to a memory leak. When data is written to the filesystem and then unmounted, the cached written data are not properly freed, resulting in permanent data leakage. This vulnerability could potentially lead to denial of service or information disclosure, making it an important security concern for Linux systems using the NTFS3 filesystem. The issue has been resolved in recent kernel updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX