Fix Use-After-Free Vulnerability in btrfs
CVE-2022-48733

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
20 June 2024

What is CVE-2022-48733?

A vulnerability in the Linux kernel's btrfs module exists where improper handling of pending snapshots during snapshot creation can lead to a use-after-free condition. When creating a snapshot, the system initializes a pending snapshot structure and links it to the transaction's list. If an error occurs during the commit process, the pending snapshot is freed without removing it from the transaction's list. This oversight may allow another task to attempt to access the now-freed snapshot during transaction commit, potentially leading to crashes or exploitation. The solution involves restructuring how pending snapshots are managed within the transaction to ensure they are only linked when error conditions following creation can be safely handled.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux c37b2b6269ee4637fb7cdb5da0d1e47215d57ce2 < 7e4c72dbaf62f8978af8321a24dbd35566d3a78a

Linux c37b2b6269ee4637fb7cdb5da0d1e47215d57ce2

Linux c37b2b6269ee4637fb7cdb5da0d1e47215d57ce2 < 9372fa1d73da5f1673921e365d0cd2c27ec7adc2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.