CVE-2022-48423: High severity Linux Linux kernel vulnerability
In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 6.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2022-48423?
CVE-2022-48423 is categorized as a high-severity vulnerability due to the potential for an out-of-bounds write in the Linux kernel.
How do I fix CVE-2022-48423?
To mitigate CVE-2022-48423, update your Linux kernel to version 6.1.3 or later.
Which versions of the Linux kernel are affected by CVE-2022-48423?
CVE-2022-48423 affects all versions of the Linux kernel prior to 6.1.3.
What components are impacted by CVE-2022-48423?
CVE-2022-48423 specifically impacts the fs/ntfs3/record.c component of the Linux kernel.
Is there a workaround for CVE-2022-48423 if I cannot update?
There are no known effective workarounds for CVE-2022-48423, so updating the kernel is the recommended action.