cbcvebase.
CVE-2022-49739
published 2025-03-27

CVE-2022-49739: In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline)…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline) inodes is within the allowed range when reading inodes from disk (gfs2_dinode_in()). This prevents us from on-disk corruption. The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just truncate inline data to the maximum allowed size don't actually make sense, and they can be removed now as well.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux>= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 45df749f827c286adbc951f2a4865b67f0442ba945df749f827c286adbc951f2a4865b67f0442ba9
linuxlinux>= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 4d4cb76636134bf9a0c9c3432dae936f999545864d4cb76636134bf9a0c9c3432dae936f99954586
linuxlinux>= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 7c414f6f06e9a3934901b6edc3177ae5a1e070947c414f6f06e9a3934901b6edc3177ae5a1e07094
linuxlinux>= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 46c9088cabd4d0469fdb61ac2a9c5003057fe94d46c9088cabd4d0469fdb61ac2a9c5003057fe94d
linuxlinux>= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < d458a0984429c2d47e60254f5bc4119cbafe83a2d458a0984429c2d47e60254f5bc4119cbafe83a2
linuxlinux>= b3b94faa5fe5968827ba0640ee9fba4b3e7f736e < 70376c7ff31221f1d21db5611d8209e677781d3a70376c7ff31221f1d21db5611d8209e677781d3a
linuxlinux_kernel< 4.19.2804.19.280
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 4.20 < 5.4.2405.4.240
linuxlinux_kernel>= 5.11 < 5.15.935.15.93
linuxlinux_kernel>= 5.16 < 6.1.116.1.11
linuxlinux_kernel>= 5.5 < 5.10.1775.10.177

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.