CVE-2022-49550

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 26, 2025
Updated: Mar 10, 2025
CWE ID 401

Summary

CVE-2022-49550 is a vulnerability affecting the Linux kernel's NTFS3 filesystem. The issue stems from the absence of the 'invalidate_folio' method in the ntfs3 filesystem, leading to a memory leak. When data is written to the filesystem and then unmounted, the cached written data are not properly freed, resulting in permanent data leakage. This vulnerability could potentially lead to denial of service or information disclosure, making it an important security concern for Linux systems using the NTFS3 filesystem. The issue has been resolved in recent kernel updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share