cbcvebase.
CVE-2022-4842
published 2023-01-12

CVE-2022-4842: A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.5th percentile
A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.8-1 (bookworm)linux 6.1.8-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 0 < 5.15.0-70.775.15.0-70.77

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu5.8MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.