PT-2025-7977 · Linux+3 · Linux Kernel+3

Axel Rasmussen

·

Publicado

2022-01-01

·

Atualizado

2025-09-29

·

CVE-2022-49049

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A issue in the Linux kernel has been resolved, related to the memfd secret functionality. When attempting to grow an existing memfd secret using ftruncate, a panic occurs due to the inability to zero part of the memory. This happens because memfd secret does not map its pages via the direct map, making the address returned by page address() useless. The patch implements a custom setattr for memfd secret that detects resizes and rejects them with EINVAL.
Recommendations For Linux kernel versions prior to the fixed version, consider applying the patch that implements a custom setattr for memfd secret to avoid the panic when growing an existing memfd secret. As a temporary workaround, avoid using ftruncate to resize memfd secret objects until a patch is available.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
BDU:2026-03821
CVE-2022-49049
RHSA-2023:2458
RHSA-2023_2458

Produtos afetados

Astra Linux
Debian
Linux Kernel
Red Hat