CVE-2022-3649: Linux Kernel BPF inode.c nilfs_new_inode use after free
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfsnewinode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211992.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3649?
CVE-2022-3649 has been classified as a problematic vulnerability in the Linux Kernel.
How do I fix CVE-2022-3649?
To mitigate CVE-2022-3649, update to a patched version of the Linux Kernel, specifically the versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
What components are affected by CVE-2022-3649?
The vulnerability affects the BPF component, particularly the function nilfs_new_inode in the file fs/nilfs2/inode.c.
Can CVE-2022-3649 be exploited remotely?
Yes, CVE-2022-3649 can be exploited remotely, making it a serious concern for systems running affected versions.
Which Linux Kernel versions are vulnerable to CVE-2022-3649?
CVE-2022-3649 affects multiple versions of the Linux Kernel, specifically versions prior to 4.9.331 and between 4.10 to 6.0.2.