cbcvebase.
CVE-2022-49381
published 2025-02-26

CVE-2022-49381: In the Linux kernel, the following vulnerability has been resolved: jffs2: fix memory leak in jffs2_do_fill_super If jffs2_iget() or d_make_root() in…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.9th percentile
In the Linux kernel, the following vulnerability has been resolved: jffs2: fix memory leak in jffs2_do_fill_super If jffs2_iget() or d_make_root() in jffs2_do_fill_super() returns an error, we can observe the following kmemleak report: unreferenced object 0xffff888105a65340 (size 64): comm "mount", pid 710, jiffies 4302851558 (age 58.239s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] kmem_cache_alloc_trace+0x475/0x8a0 [] jffs2_sum_init+0x96/0x1a0 [] jffs2_do_mount_fs+0x745/0x2120 [] jffs2_do_fill_super+0x35c/0x810 [] jffs2_fill_super+0x2b9/0x3b0 [...] unreferenced object 0xffff8881bd7f0000 (size 65536): comm "mount", pid 710, jiffies 4302851558 (age 58.239s) hex dump (first 32 bytes): bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb ................ bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb ................ backtrace: [] kmalloc_order+0xda/0x110 [] kmalloc_order_trace+0x21/0x130 [] __kmalloc+0x711/0x8a0 [] jffs2_sum_init+0xd9/0x1a0 [] jffs2_do_mount_fs+0x745/0x2120 [] jffs2_do_fill_super+0x35c/0x810 [] jffs2_fill_super+0x2b9/0x3b0 [...] This is because the resources allocated in jffs2_sum_init() are not released. Call jffs2_sum_exit() to release these resources to solve the problem.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 4ba7bbeab8009faf3a726e565d98816593ddd5b04ba7bbeab8009faf3a726e565d98816593ddd5b0
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 4da8763a3d2b684c773b72ed80fad40bc264bc404da8763a3d2b684c773b72ed80fad40bc264bc40
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 28048a4cf3813b7cf5cc8cce629dfdc7951cb1c228048a4cf3813b7cf5cc8cce629dfdc7951cb1c2
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < d3a4fff1e7e408c32649030daa7c2c42a7e19a95d3a4fff1e7e408c32649030daa7c2c42a7e19a95
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 3252d327f977b14663a10967f3b0930d6c3256873252d327f977b14663a10967f3b0930d6c325687
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < ecc53e58596542791e82eff00702f8af7a313f70ecc53e58596542791e82eff00702f8af7a313f70
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < cf9db013e167bc8fc2ecd7a13ed97a37df0c9dabcf9db013e167bc8fc2ecd7a13ed97a37df0c9dab
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < 69295267c481545f636b69ff341b8db75aa136b969295267c481545f636b69ff341b8db75aa136b9
linuxlinux>= e631ddba588783edd521c5a89f7b2902772fb691 < c14adb1cf70a984ed081c67e9d27bc3caad9537cc14adb1cf70a984ed081c67e9d27bc3caad9537c
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 2.6.15 < 4.9.3184.9.318
linuxlinux_kernel>= 4.10 < 4.14.2834.14.283
linuxlinux_kernel>= 4.15 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.475.15.47
linuxlinux_kernel>= 5.16 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4
linuxlinux_kernel>= 5.5 < 5.10.1225.10.122

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.