THREAT OPS › Threat News › [NVD] CVE-2022-49770 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved:
ceph: avoid putting the realm twice when decoding snaps fails
When decoding the snaps fails it maybe leaving the 'first_realm'
and 'realm' pointing to the same snaprealm memory. And then it'll
put it twice and
[NVD] CVE-2022-49770 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it'll put it twice and
CVE-2022-49770 CVSS: 9.8 CRITICAL Published: 2025-05-01T15:15:59.920
In the Linux kernel, the following vulnerability has been resolved:
ceph: avoid putting the realm twice when decoding snaps fails
When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it'll put it twice and could cause random use-after-free, BUG_ON, etc iss
Indicators of compromise
- CVE-2022-49770cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-49770