#VU104813 Infinite loop in Linux kernel - CVE-2022-49352


Vulnerability identifier: #VU104813

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-49352

CWE-ID: CWE-835

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the ext4_setattr() function in fs/ext4/inode.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/0ab308d72af7548f21e4499d025c25887da0c26a
https://git.kernel.org/stable/c/1bcce88da60eccc946c0f4ed942b0f08cd565778
https://git.kernel.org/stable/c/adf490083ca52ebfb0b2fe64ff1ead00c0452dd7
https://git.kernel.org/stable/c/b81d2ff6885e38fc745eeaf9565775055778fc0b
https://git.kernel.org/stable/c/e383c2aa5f02ab571530dc5c5696479672478c25
https://git.kernel.org/stable/c/f4534c9fc94d22383f187b9409abb3f9df2e3db3


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability