CVE-2022-48946

MEDIUM

Linux Kernel Memory Corruption in UDF Preallocation Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: udf: Fix preallocation discarding at indirect extent boundary When preallocation extent is the first one in the extent block, the code would corrupt extent tree header instead. Fix the problem and use udf_delete_aext() for deleting extent to avoid some code duplication.

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 16.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (31)
linux/Kernel 2.6.12 - 4.9.337linux
linux/Kernel 4.10.0 - 4.14.303linux
linux/Kernel 4.15.0 - 4.19.270linux
linux/Kernel 4.20.0 - 5.4.229linux
linux/Kernel 5.11.0 - 5.15.85linux
linux/Kernel 5.16.0 - 6.0.15linux
linux/Kernel 5.5.0 - 5.10.161linux
linux/Kernel 6.1.0 - 6.1.1linux
Linux/Linux < 2.6.12
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 12a88f572d6d94b5c0b72e2d1782cc2e96ac06cf
... and 21 more
Published Oct 21, 2024
Tracked Since Feb 18, 2026