CVE-2022-49739
published 2025-03-27CVE-2022-49739: In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline)…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
gfs2: Always check inode size of inline inodes
Check if the inode size of stuffed (inline) inodes is within the allowed
range when reading inodes from disk (gfs2_dinode_in()). This prevents
us from on-disk corruption.
The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just
truncate inline data to the maximum allowed size don't actually make
sense, and they can be removed now as well.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.11-1 (bookworm) | linux 6.1.11-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 45df749f827c286adbc951f2a4865b67f0442ba9 | 45df749f827c286adbc951f2a4865b67f0442ba9 |
| linux | linux | >= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 4d4cb76636134bf9a0c9c3432dae936f99954586 | 4d4cb76636134bf9a0c9c3432dae936f99954586 |
| linux | linux | >= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 7c414f6f06e9a3934901b6edc3177ae5a1e07094 | 7c414f6f06e9a3934901b6edc3177ae5a1e07094 |
| linux | linux | >= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 46c9088cabd4d0469fdb61ac2a9c5003057fe94d | 46c9088cabd4d0469fdb61ac2a9c5003057fe94d |
| linux | linux | >= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < d458a0984429c2d47e60254f5bc4119cbafe83a2 | d458a0984429c2d47e60254f5bc4119cbafe83a2 |
| linux | linux | >= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 70376c7ff31221f1d21db5611d8209e677781d3a | 70376c7ff31221f1d21db5611d8209e677781d3a |
| linux | linux_kernel | < 4.19.280 | 4.19.280 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 4.20 < 5.4.240 | 5.4.240 |
| linux | linux_kernel | >= 5.11 < 5.15.93 | 5.15.93 |
| linux | linux_kernel | >= 5.16 < 6.1.11 | 6.1.11 |
| linux | linux_kernel | >= 5.5 < 5.10.177 | 5.10.177 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: gfs2: Always check inode size of inline inodes
vendor_redhat·2025-03-27·CVSS 5.5
CVE-2022-49739 [MEDIUM] kernel: gfs2: Always check inode size of inline inodes
kernel: gfs2: Always check inode size of inline inodes
In the Linux kernel, the following vulnerability has been resolved:
gfs2: Always check inode size of inline inodes
Check if the inode size of stuffed (inline) inodes is within the allowed
range when reading inodes from disk (gfs2_dinode_in()). This prevents
us from on-disk corruption.
The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just
truncate inline data to the maximum allowed size don't actually make
sense, and they can be removed now as well.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2022-49739: linux - In the Linux kernel, the following vulnerability has been resolved: gfs2: Alway...
vendor_debian·2022·CVSS 5.5
CVE-2022-49739 [MEDIUM] CVE-2022-49739: linux - In the Linux kernel, the following vulnerability has been resolved: gfs2: Alway...
In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline) inodes is within the allowed range when reading inodes from disk (gfs2_dinode_in()). This prevents us from on-disk corruption. The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just truncate inline data to the maximum allowed size don't actually make sense, and they can be removed now as well.
Scope: local
bookworm: resolved (fixed in 6.1.11-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.11-1)
sid: resolved (fixed in 6.1.11-1)
trixie: resolved (fixed in 6.1.11-1)
OSV
CVE-2022-49739: In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed
osv·2025-03-27·CVSS 5.5
CVE-2022-49739 [MEDIUM] CVE-2022-49739: In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed
In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline) inodes is within the allowed range when reading inodes from disk (gfs2_dinode_in()). This prevents us from on-disk corruption. The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just truncate inline data to the maximum allowed size don't actually make sense, and they can be removed now as well.
GHSA
GHSA-xhmw-hwm7-v657: In the Linux kernel, the following vulnerability has been resolved:
gfs2: Always check inode size of inline inodes
Check if the inode size of stuffe
ghsa_unreviewed·2025-03-27
CVE-2022-49739 [MEDIUM] GHSA-xhmw-hwm7-v657: In the Linux kernel, the following vulnerability has been resolved:
gfs2: Always check inode size of inline inodes
Check if the inode size of stuffe
In the Linux kernel, the following vulnerability has been resolved:
gfs2: Always check inode size of inline inodes
Check if the inode size of stuffed (inline) inodes is within the allowed
range when reading inodes from disk (gfs2_dinode_in()). This prevents
us from on-disk corruption.
The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just
truncate inline data to the maximum allowed size don't actually make
sense, and they can be removed now as well.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/45df749f827c286adbc951f2a4865b67f0442ba9https://git.kernel.org/stable/c/46c9088cabd4d0469fdb61ac2a9c5003057fe94dhttps://git.kernel.org/stable/c/4d4cb76636134bf9a0c9c3432dae936f99954586https://git.kernel.org/stable/c/70376c7ff31221f1d21db5611d8209e677781d3ahttps://git.kernel.org/stable/c/7c414f6f06e9a3934901b6edc3177ae5a1e07094https://git.kernel.org/stable/c/d458a0984429c2d47e60254f5bc4119cbafe83a2
2025-03-27
Published