CVE-2022-48424: High severity linux kernel vulnerability
Published Mar 19, 2023
·Updated
In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate the attribute name offset. An unhandled page fault may occur.
Affected Software
4 affected componentsFixes available
Linux Linux kernel>=5.15<5.15.87
Linux Linux kernel>=5.16<6.0.17
Linux Linux kernel>=6.1<6.1.3
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
Remediation
Patch Available
Event History
Mar 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:13 AM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·03:59 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·05:15 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48424?
CVE-2022-48424 has a significant severity as it leads to unhandled page faults in the Linux kernel.
2
How do I fix CVE-2022-48424?
To remediate CVE-2022-48424, update the Linux Kernel to versions 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.11-1, or 6.12.12-1.
3
Which versions of the Linux Kernel are affected by CVE-2022-48424?
CVE-2022-48424 affects Linux Kernel versions prior to 6.1.3 and versions from 5.15 to 6.0.17.
4
What components of the Linux Kernel are involved in CVE-2022-48424?
CVE-2022-48424 involves the fs/ntfs3/inode.c component of the Linux Kernel.
5
Is CVE-2022-48424 a historical vulnerability?
CVE-2022-48424 was addressed in the kernel updates released after version 6.1.3, making it a historical vulnerability.