cbcvebase.
CVE-2022-49166
published 2025-02-26

CVE-2022-49166: In the Linux kernel, the following vulnerability has been resolved: ntfs: add sanity check on allocation size ntfs_read_inode_mount invokes ntfs_malloc_nofs…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ntfs: add sanity check on allocation size ntfs_read_inode_mount invokes ntfs_malloc_nofs with zero allocation size. It triggers one BUG in the __ntfs_malloc function. Fix this by adding sanity check on ni->attr_list_size.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < bd8d7daa0e53b184a2f3c6e0d47330780d0a0650bd8d7daa0e53b184a2f3c6e0d47330780d0a0650
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 21d490232f323ed4053eb9924615e6fea291f15421d490232f323ed4053eb9924615e6fea291f154
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 07793d2e55563124108762f4e5f811db92ffe02f07793d2e55563124108762f4e5f811db92ffe02f
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fe41ad8be036a3de3e4bdde709551aeb4de2fe7dfe41ad8be036a3de3e4bdde709551aeb4de2fe7d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b230f2d9441a34c7f483d39ab78519bcf73cc2e0b230f2d9441a34c7f483d39ab78519bcf73cc2e0
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 24ab2d4ef52c2dbb62a60844b87fc8872383407a24ab2d4ef52c2dbb62a60844b87fc8872383407a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 115fae2c1566eacc5ad2055f72521354612e72c3115fae2c1566eacc5ad2055f72521354612e72c3
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c641087d381a08363e5f14179bc6b0a23eca7c47c641087d381a08363e5f14179bc6b0a23eca7c47
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 714fbf2647b1a33d914edd695d4da92029c7e7c0714fbf2647b1a33d914edd695d4da92029c7e7c0
linuxlinux_kernel< 4.9.3114.9.311
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.10 < 4.14.2764.14.276
linuxlinux_kernel>= 4.15 < 4.19.2384.19.238
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.