PT-2025-8352 · Linux +2 · Linux Kernel +2

Trond Myklebust

·

Published

2025-02-26

·

Updated

2025-04-14

·

CVE-2022-49418

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.

Name of the Vulnerable Software and Affected Versions:

Linux kernel (affected versions not specified)

Description:

A vulnerability in the Linux kernel has been resolved, related to the NFSv4 protocol. The issue occurred during referral lookup, where an uninitialized `nfs4 label` was freed, causing a crash. The problem was fixed by sending the already-allocated `fattr` along with `nfs4 fs locations` and dropping the `memcpy` of `fattr`. This fix resolves a crash that occurred when the `ls` command was executed.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-49418
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1

Affected Products

Astra Linux
Linux Kernel
Suse