CVE-2022-48425: High severity linux kernel vulnerability
Published Mar 19, 2023
·Updated
In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs.
Affected Software
5 affected componentsFixes available
Linux Linux kernel<=6.2.7
Linux Linux kernel>=5.15<5.15.113
Linux Linux kernel>=5.16<6.1.33
Linux Linux kernel>=6.2<6.3.4
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1
Remediation
Event History
Mar 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:13 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·05:20 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:20 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48425?
CVE-2022-48425 is rated as a medium severity vulnerability due to the potential for memory corruption.
2
How do I fix CVE-2022-48425?
To fix CVE-2022-48425, update to a patched version of the Linux kernel that does not contain this vulnerability.
3
What versions of the Linux Kernel are affected by CVE-2022-48425?
CVE-2022-48425 affects Linux Kernel versions from 5.15 to 6.2.7 inclusive.
4
What component is impacted by CVE-2022-48425?
CVE-2022-48425 impacts the fs/ntfs3/inode.c component of the Linux kernel.
5
When was CVE-2022-48425 last updated?
CVE-2022-48425 was last updated on 29 November 2024.