CVE-2022-49064
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49064 affects the Linux kernel's cachefiles component. The vulnerability was discovered when an inode in-use flag leakage was identified in the cachefilesopenfile() and cachefilescreatetmpfile() functions. This issue was resolved in the Linux kernel through a patch that properly unmarks inodes in error paths (Kernel Git).

Technical details

The vulnerability exists in the Linux kernel's cachefiles subsystem where the inode in-use flag wasn't being properly cleared in error paths. When the in-use flag leakage occurs in cachefilesopenfile(), the system would incorrectly complain "Inode already in use" when another cookie with the same index key is looked up. Similarly, while the leakage in cachefilescreatetmpfile() wouldn't trigger the warning, it still represented an implementation flaw (Debian Security).

Impact

When exploited, this vulnerability could lead to resource leakage in the Linux kernel's cachefiles system. The main impact is that the system would incorrectly mark inodes as in-use, potentially preventing legitimate operations from accessing these resources and causing "Inode already in use" errors (Kernel Git).

Mitigation and workarounds

The vulnerability has been fixed in various Linux distributions. For Debian, the fix is available in linux version 5.10.223-1 for bullseye, 6.1.129-1 for bookworm, and 6.12.17-1 for sid/trixie. The patch implements proper unmarking of inodes in error paths by adding a new cachefilesdounmarkinodein_use function (Debian Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-iot
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-rt-devel-matched
NoYesDec 09, 2025
CVE-2025-40340MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-hwe
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-core
NoYesDec 09, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • libperf-devel
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management