cbcvebase.
CVE-2022-48923
published 2024-08-22

CVE-2022-48923: In the Linux kernel, the following vulnerability has been resolved: btrfs: prevent copying too big compressed lzo segment Compressed length can be corrupted to…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: prevent copying too big compressed lzo segment Compressed length can be corrupted to be a lot larger than memory we have allocated for buffer. This will cause memcpy in copy_compressed_segment to write outside of allocated memory. This mostly results in stuck read syscall but sometimes when using btrfs send can get #GP kernel: general protection fault, probably for non-canonical address 0x841551d5c1000: 0000 [#1] PREEMPT SMP NOPTI kernel: CPU: 17 PID: 264 Comm: kworker/u256:7 Tainted: P OE 5.17.0-rc2-1 #12 kernel: Workqueue: btrfs-endio btrfs_work_helper [btrfs] kernel: RIP: 0010:lzo_decompress_bio (./include/linux/fortify-string.h:225 fs/btrfs/lzo.c:322 fs/btrfs/lzo.c:394) btrfs Code starting with the faulting instruction 0:* 48 8b 06 mov (%rsi),%rax kernel: end_compressed_bio_read (fs/btrfs/compression.c:104 fs/btrfs/compression.c:1363 fs/btrfs/compression.c:323) btrfs kernel: end_workqueue_fn (fs/btrfs/disk-io.c:1923) btrfs kernel: btrfs_work_helper (fs/btrfs/async-thread.c:326) btrfs kernel: process_one_work (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:212 ./include/trace/events/workqueue.h:108 kernel/workqueue.c:2312) kernel: worker_thread (./include/linux/list.h:292 kernel/workqueue.c:2455) kernel: ? process_one_work (kernel/workqueue.c:2397) kernel: kthread (kernel/kthread.c:377) kernel: ? kthread_complete_and_exit (kernel/kthread.c:332) kernel: ret_from_fork (arch/x86/entry/entry_64.S:301) kernel:

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.12-1 (bookworm)linux 5.16.12-1 (bookworm)
linuxlinux
linuxlinux>= a6e66e6f8c1b685e11b778bef614480a9c1a5278 < 8df508b7a44cd8110c726057cd28e8f8116885eb8df508b7a44cd8110c726057cd28e8f8116885eb
linuxlinux>= a6e66e6f8c1b685e11b778bef614480a9c1a5278 < e326bd06cdde46df952361456232022298281d16e326bd06cdde46df952361456232022298281d16
linuxlinux>= a6e66e6f8c1b685e11b778bef614480a9c1a5278 < 741b23a970a79d5d3a1db2d64fa2c7b375a4febb741b23a970a79d5d3a1db2d64fa2c7b375a4febb
linuxlinux_kernel< 5.15.265.15.26
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 5.16 < 5.16.125.16.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.