PT-2025-18616 · Linux+1 · Linux Kernel+1

Published

2025-05-01

·

Updated

2025-05-02

·

CVE-2022-49899

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved. The issue was related to the use of the keyrings subsystem for managing fscrypt master key structs. This approach led to several problems, including the inability to guarantee the destruction of master keys, potential deadlocks, and undesirable delays in key destruction. The vulnerability allowed for a use-after-free condition and made it difficult to ensure that all secrets were wiped. The fix involves changing the implementation to store master key structs in a regular kernel data structure and reworking the reference counting, locking, and lifetime accordingly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-49899

Affected Products

Astra Linux
Linux Kernel