CVE-2022-3649
LOWLinux Kernel < 4.9.331 - Use-After-Free in nilfs_new_inode
Title source: llmDescription
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211992.
References (5)
Core 5
Core References
Mailing List, Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=d325dc6eb763c10f591c239550b8c7e5466a5d09
Third Party Advisory
https://security.netapp.com/advisory/ntap-20230214-0009/
Third Party Advisory
https://vuldb.com/?id.211992
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html
Scores
CVSS v3
3.1
EPSS
0.0008
EPSS Percentile
23.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-119
CWE-416
Status
published
Products (7)
debian/debian_linux
10.0
linux/linux_kernel
< 4.9.331
netapp/active_iq_unified_manager
netapp/h300s_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
Published
Oct 21, 2022
Tracked Since
Feb 18, 2026