PT-2025-18616 · Linux+1 · Linux Kernel+1
Published
2025-05-01
·
Updated
2025-05-02
·
CVE-2022-49899
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved. The issue was related to the use of the keyrings subsystem for managing fscrypt master key structs. This approach led to several problems, including the inability to guarantee the destruction of master keys, potential deadlocks, and undesirable delays in key destruction. The vulnerability allowed for a use-after-free condition and made it difficult to ensure that all secrets were wiped. The fix involves changing the implementation to store master key structs in a regular kernel data structure and reworking the reference counting, locking, and lifetime accordingly.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel