
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-49064 affects the Linux kernel's cachefiles component. The vulnerability was discovered when an inode in-use flag leakage was identified in the cachefilesopenfile() and cachefilescreatetmpfile() functions. This issue was resolved in the Linux kernel through a patch that properly unmarks inodes in error paths (Kernel Git).
The vulnerability exists in the Linux kernel's cachefiles subsystem where the inode in-use flag wasn't being properly cleared in error paths. When the in-use flag leakage occurs in cachefilesopenfile(), the system would incorrectly complain "Inode already in use" when another cookie with the same index key is looked up. Similarly, while the leakage in cachefilescreatetmpfile() wouldn't trigger the warning, it still represented an implementation flaw (Debian Security).
When exploited, this vulnerability could lead to resource leakage in the Linux kernel's cachefiles system. The main impact is that the system would incorrectly mark inodes as in-use, potentially preventing legitimate operations from accessing these resources and causing "Inode already in use" errors (Kernel Git).
The vulnerability has been fixed in various Linux distributions. For Debian, the fix is available in linux version 5.10.223-1 for bullseye, 6.1.129-1 for bookworm, and 6.12.17-1 for sid/trixie. The patch implements proper unmarking of inodes in error paths by adding a new cachefilesdounmarkinodein_use function (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."