cbcvebase.
CVE-2022-48877
published 2024-08-21

CVE-2022-48877: In the Linux kernel, the following vulnerability has been resolved: f2fs: let's avoid panic if extent_tree is not created This patch avoids the below panic. pc…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: let's avoid panic if extent_tree is not created This patch avoids the below panic. pc : __lookup_extent_tree+0xd8/0x760 lr : f2fs_do_write_data_page+0x104/0x87c sp : ffffffc010cbb3c0 x29: ffffffc010cbb3e0 x28: 0000000000000000 x27: ffffff8803e7f020 x26: ffffff8803e7ed40 x25: ffffff8803e7f020 x24: ffffffc010cbb460 x23: ffffffc010cbb480 x22: 0000000000000000 x21: 0000000000000000 x20: ffffffff22e90900 x19: 0000000000000000 x18: ffffffc010c5d080 x17: 0000000000000000 x16: 0000000000000020 x15: ffffffdb1acdbb88 x14: ffffff888759e2b0 x13: 0000000000000000 x12: ffffff802da49000 x11: 000000000a001200 x10: ffffff8803e7ed40 x9 : ffffff8023195800 x8 : ffffff802da49078 x7 : 0000000000000001 x6 : 0000000000000000 x5 : 0000000000000006 x4 : ffffffc010cbba28 x3 : 0000000000000000 x2 : ffffffc010cbb480 x1 : 0000000000000000 x0 : ffffff8803e7ed40 Call trace: __lookup_extent_tree+0xd8/0x760 f2fs_do_write_data_page+0x104/0x87c f2fs_write_single_data_page+0x420/0xb60 f2fs_write_cache_pages+0x418/0xb1c __f2fs_write_data_pages+0x428/0x58c f2fs_write_data_pages+0x30/0x40 do_writepages+0x88/0x190 __writeback_single_inode+0x48/0x448 writeback_sb_inodes+0x468/0x9e8 __writeback_inodes_wb+0xb8/0x2a4 wb_writeback+0x33c/0x740 wb_do_writeback+0x2b4/0x400 wb_workfn+0xe4/0x34c process_one_work+0x24c/0x5bc worker_thread+0x3e8/0xa50 kthread+0x150/0x1b4

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.8-1 (bookworm)linux 6.1.8-1 (bookworm)
linuxlinux
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < dd83a9763e29ed7a21c8a43f7a62cd0a6bf74692dd83a9763e29ed7a21c8a43f7a62cd0a6bf74692
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < ff85a1dbd90d29f73033177ff8d8de4a27d9721cff85a1dbd90d29f73033177ff8d8de4a27d9721c
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 557e85ff9afef6d45020b6f09357111d38033c31557e85ff9afef6d45020b6f09357111d38033c31
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 72009139a661ade5cb1da4239734ed02fa1cfff072009139a661ade5cb1da4239734ed02fa1cfff0
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 2c129e868992621a739bdd57a5bffa3985ef1b912c129e868992621a739bdd57a5bffa3985ef1b91
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 1c38cdc747f00daf7394535eae5afc4c503c59bb1c38cdc747f00daf7394535eae5afc4c503c59bb
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < df9d44b645b83fffccfb4e28c1f93376585fdec8df9d44b645b83fffccfb4e28c1f93376585fdec8
linuxlinux_kernel< 4.14.3044.14.304
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 0 < 6.1.8-16.1.8-1
linuxlinux_kernel>= 4.15 < 4.19.2714.19.271
linuxlinux_kernel>= 4.20 < 5.4.2305.4.230
linuxlinux_kernel>= 5.11 < 5.15.905.15.90
linuxlinux_kernel>= 5.16 < 6.1.86.1.8
linuxlinux_kernel>= 5.5 < 5.10.1655.10.165

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.