HIGH
kernel: ntfs3: invalid kfree in fs/ntfs3/inode.c
Published Mar 19, 2023
7.8
HIGHCVSS 3.1
EPSS 0.25%
Description
In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs.
Affected products
No data.
OR
- ≥ 5.15 · < 5.15.113
- ≥ 5.16 · < 6.1.33
- ≥ 6.2 · < 6.3.4
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not affected by this flaw as it does not include support for the NTFS3 file system driver.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-48425 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2179841 Issue Tracking
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=467333af2f7b95eeaa61a5b5369a80063cd971fd Patch
- https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/fs/ntfs3?id=467333af2f7b95eeaa61a5b5369a80063cd971fd Patch
- https://nvd.nist.gov/vuln/detail/CVE-2022-48425
- https://security.netapp.com/advisory/ntap-20230413-0006/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-48425
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 19, 2023
Updated Feb 26, 2025
Reserved Mar 19, 2023
Link CVE-2022-48425
CISA Vulnrichment
Updated Feb 26, 2025