cbcvebase.
CVE-2022-49277
published 2025-02-26

CVE-2022-49277: In the Linux kernel, the following vulnerability has been resolved: jffs2: fix memory leak in jffs2_do_mount_fs If jffs2_build_filesystem() in…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.0th percentile
In the Linux kernel, the following vulnerability has been resolved: jffs2: fix memory leak in jffs2_do_mount_fs If jffs2_build_filesystem() in jffs2_do_mount_fs() returns an error, we can observe the following kmemleak report: unreferenced object 0xffff88811b25a640 (size 64): comm "mount", pid 691, jiffies 4294957728 (age 71.952s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] kmem_cache_alloc_trace+0x584/0x880 [] jffs2_sum_init+0x86/0x130 [] jffs2_do_mount_fs+0x798/0xac0 [] jffs2_do_fill_super+0x383/0xc30 [] jffs2_fill_super+0x2ea/0x4c0 [...] unreferenced object 0xffff88812c760000 (size 65536): comm "mount", pid 691, jiffies 4294957728 (age 71.952s) hex dump (first 32 bytes): bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb ................ bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb ................ backtrace: [] __kmalloc+0x6b9/0x910 [] jffs2_sum_init+0xd7/0x130 [] jffs2_do_mount_fs+0x798/0xac0 [] jffs2_do_fill_super+0x383/0xc30 [] jffs2_fill_super+0x2ea/0x4c0 [...] This is because the resources allocated in jffs2_sum_init() are not released. Call jffs2_sum_exit() to release these resources to solve the problem.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 2a9d8184458562e6bf2f40d0e677fc85e2dd38342a9d8184458562e6bf2f40d0e677fc85e2dd3834
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 9a0f6610c7daedd2eace430beeb08a8b7ac806999a0f6610c7daedd2eace430beeb08a8b7ac80699
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < dbe0d0521eaa6a3d235517319266c539bb5c5112dbe0d0521eaa6a3d235517319266c539bb5c5112
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 0978e9af4559a171ac7a74a1b3ef21804b0a0fa90978e9af4559a171ac7a74a1b3ef21804b0a0fa9
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 607d3aab7349f18e0d9dba4100d09d16fe27caca607d3aab7349f18e0d9dba4100d09d16fe27caca
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 4392e8aeebc5a4f8073620bccba7de1b1f6d7c884392e8aeebc5a4f8073620bccba7de1b1f6d7c88
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 5f34310d1376ca5b2ed798258def2c2ab3cc66995f34310d1376ca5b2ed798258def2c2ab3cc6699
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < c94128470e6fe53d9bd9d16d2d3271813f9d37afc94128470e6fe53d9bd9d16d2d3271813f9d37af
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < d051cef784de4d54835f6b6836d98a8f6935772cd051cef784de4d54835f6b6836d98a8f6935772c
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 2.6.15 < 4.9.3114.9.311
linuxlinux_kernel>= 4.10 < 4.14.2764.14.276
linuxlinux_kernel>= 4.15 < 4.19.2384.19.238
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.