CVE-2022-49166

MEDIUM EPSS 15.7%
Published Feb 26, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Feb 26, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ntfs: add sanity check on allocation size ntfs_read_inode_mount invokes ntfs_malloc_nofs with zero allocation size. It triggers one BUG in the __ntfs_malloc function. Fix this by adding sanity check on ni->attr_list_size.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
15.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 8

VendorProductVersionRange
linuxlinux_kernel* <4.9.311
linuxlinux_kernel*≥4.10  –  <4.14.276
linuxlinux_kernel*≥4.15  –  <4.19.238
linuxlinux_kernel*≥4.20  –  <5.4.189
linuxlinux_kernel*≥5.5  –  <5.10.110
linuxlinux_kernel*≥5.11  –  <5.15.33
linuxlinux_kernel*≥5.16  –  <5.16.19
linuxlinux_kernel*≥5.17  –  <5.17.2

References 9

  • git.kernel.org https://git.kernel.org/stable/c/07793d2e55563124108762f4e5f811db92ffe02f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/115fae2c1566eacc5ad2055f72521354612e72c3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/21d490232f323ed4053eb9924615e6fea291f154
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/24ab2d4ef52c2dbb62a60844b87fc8872383407a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/714fbf2647b1a33d914edd695d4da92029c7e7c0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b230f2d9441a34c7f483d39ab78519bcf73cc2e0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bd8d7daa0e53b184a2f3c6e0d47330780d0a0650
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c641087d381a08363e5f14179bc6b0a23eca7c47
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fe41ad8be036a3de3e4bdde709551aeb4de2fe7d
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/07793d2e55563124108762f4e5f811db92ffe02f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/115fae2c1566eacc5ad2055f72521354612e72c3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/21d490232f323ed4053eb9924615e6fea291f154
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/24ab2d4ef52c2dbb62a60844b87fc8872383407a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/714fbf2647b1a33d914edd695d4da92029c7e7c0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b230f2d9441a34c7f483d39ab78519bcf73cc2e0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bd8d7daa0e53b184a2f3c6e0d47330780d0a0650
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c641087d381a08363e5f14179bc6b0a23eca7c47
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fe41ad8be036a3de3e4bdde709551aeb4de2fe7d
    Patch