cbcvebase.
CVE-2022-49282
published 2025-02-26

CVE-2022-49282: In the Linux kernel, the following vulnerability has been resolved: f2fs: quota: fix loop condition at f2fs_quota_sync() cnt should be passed to…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.3th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: quota: fix loop condition at f2fs_quota_sync() cnt should be passed to sb_has_quota_active() instead of type to check active quota properly. Moreover, when the type is -1, the compiler with enough inline knowledge can discard sb_has_quota_active() check altogether, causing a NULL pointer dereference at the following inode_lock(dqopt->files[cnt]): [ 2.796010] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a0 [ 2.796024] Mem abort info: [ 2.796025] ESR = 0x96000005 [ 2.796028] EC = 0x25: DABT (current EL), IL = 32 bits [ 2.796029] SET = 0, FnV = 0 [ 2.796031] EA = 0, S1PTW = 0 [ 2.796032] Data abort info: [ 2.796034] ISV = 0, ISS = 0x00000005 [ 2.796035] CM = 0, WnR = 0 [ 2.796046] user pgtable: 4k pages, 39-bit VAs, pgdp=00000003370d1000 [ 2.796048] [00000000000000a0] pgd=0000000000000000, pud=0000000000000000 [ 2.796051] Internal error: Oops: 96000005 [#1] PREEMPT SMP [ 2.796056] CPU: 7 PID: 640 Comm: f2fs_ckpt-259:7 Tainted: G S 5.4.179-arter97-r8-64666-g2f16e087f9d8 #1 [ 2.796057] Hardware name: Qualcomm Technologies, Inc. Lahaina MTP lemonadep (DT) [ 2.796059] pstate: 80c00005 (Nzcv daif +PAN +UAO) [ 2.796065] pc : down_write+0x28/0x70 [ 2.796070] lr : f2fs_quota_sync+0x100/0x294 [ 2.796071] sp : ffffffa3f48ffc30 [ 2.796073] x29: ffffffa3f48ffc30 x28: 0000000000000000 [ 2.796075] x27: ffffffa3f6d718b8 x26: ffffffa415fe9d80 [ 2.796077] x25: ffffffa3f7290048 x24: 0000000000000001 [ 2.796078] x23: 0000000000000000 x22: ffffffa3f7290000 [ 2.796080] x21: ffffffa3f72904a0 x20: ffffffa3f7290110 [ 2.796081] x19: ffffffa3f77a9800 x18: ffffffc020aae038 [ 2.796083] x17: ffffffa40e38e040 x16: ffffffa40e38e6d0 [ 2.796085] x15: ffffffa40e38e6cc x14: ffffffa40e38e6d0 [ 2.796086] x13: 00000000000004f6 x12: 00162c44ff493000 [ 2.796088] x11: 0000000000000400 x10: ffffffa40e38c948 [ 2.796090] x9 : 0000000000000000 x8 : 00000000000000a0 [ 2.796091] x7 : 0000000000000000 x

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2d586a3f5b7ec2f5a939db4abc9aa053c237545c < e58ee6bd939b773675240f5d0f5b88a367c037c4e58ee6bd939b773675240f5d0f5b88a367c037c4
linuxlinux>= 5.10.67 < 5.10.1105.10.110
linuxlinux>= 5.13.19 < 5.145.14
linuxlinux>= 5.14.6 < 5.155.15
linuxlinux>= 5.4.148 < 5.4.1895.4.189
linuxlinux>= 9de71ede81e6d1a111fdd868b2d78d459fa77f80 < f9156db0987f1b426015d56505e2c58dee70c90df9156db0987f1b426015d56505e2c58dee70c90d
linuxlinux>= 9de71ede81e6d1a111fdd868b2d78d459fa77f80 < e9ebf1e8fc50b6a9336f9aea1082d7845e568d0ee9ebf1e8fc50b6a9336f9aea1082d7845e568d0e
linuxlinux>= 9de71ede81e6d1a111fdd868b2d78d459fa77f80 < 724469814d805820cd37ea789769dba94123ff1a724469814d805820cd37ea789769dba94123ff1a
linuxlinux>= 9de71ede81e6d1a111fdd868b2d78d459fa77f80 < 680af5b824a52faa819167628665804a14f0e0df680af5b824a52faa819167628665804a14f0e0df
linuxlinux>= a02982545e61020c23f411b073ba5171381138e4 < f1d5946d47c0827bae39e1537959ce8d6f0224c5f1d5946d47c0827bae39e1537959ce8d6f0224c5
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.10.67 < 5.10.1105.10.110
linuxlinux_kernel>= 5.13.19 < 5.145.14
linuxlinux_kernel>= 5.14.6 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.4.148 < 5.4.1895.4.189

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.