CVE-2022-49747
published 2025-03-27CVE-2022-49747: In the Linux kernel, the following vulnerability has been resolved: erofs/zmap.c: Fix incorrect offset calculation Effective offset to add to length was being…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
erofs/zmap.c: Fix incorrect offset calculation
Effective offset to add to length was being incorrectly calculated,
which resulted in iomap->length being set to 0, triggering a WARN_ON
in iomap_iter_done().
Fix that, and describe it in comments.
This was reported as a crash by syzbot under an issue about a warning
encountered in iomap_iter_done(), but unrelated to erofs.
C reproducer: https://syzkaller.appspot.com/text?tag=ReproC&x=1037a6b2880000
Kernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=e2021a61197ebe02
Dashboard link: https://syzkaller.appspot.com/bug?extid=a8e049cd3abd342936b6
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.11-1 (bookworm) | linux 6.1.11-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= eadcd6b5a1eb39866ab8d8a3e4f2e51bc51a2350 < 2144859229c1e74f52d3ea067338d314a83a8afb | 2144859229c1e74f52d3ea067338d314a83a8afb |
| linux | linux | >= eadcd6b5a1eb39866ab8d8a3e4f2e51bc51a2350 < 9f31d8c889d9a4e47bfcc6c4537d0c9f89fe582c | 9f31d8c889d9a4e47bfcc6c4537d0c9f89fe582c |
| linux | linux | >= eadcd6b5a1eb39866ab8d8a3e4f2e51bc51a2350 < 6acd87d50998ef0afafc441613aeaf5a8f5c9eff | 6acd87d50998ef0afafc441613aeaf5a8f5c9eff |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 0 < 6.1.11-1 | 6.1.11-1 |
| linux | linux_kernel | >= 5.15 < 5.15.92 | 5.15.92 |
| linux | linux_kernel | >= 5.16 < 6.1.10 | 6.1.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: erofs/zmap.c: Fix incorrect offset calculation
vendor_redhat·2025-03-27·CVSS 5.5
CVE-2022-49747 [MEDIUM] CWE-682 kernel: erofs/zmap.c: Fix incorrect offset calculation
kernel: erofs/zmap.c: Fix incorrect offset calculation
In the Linux kernel, the following vulnerability has been resolved:
erofs/zmap.c: Fix incorrect offset calculation
Effective offset to add to length was being incorrectly calculated,
which resulted in iomap->length being set to 0, triggering a WARN_ON
in iomap_iter_done().
Fix that, and describe it in comments.
This was reported as a crash by syzbot under an issue about a warning
encountered in iomap_iter_done(), but unrelated to erofs.
C reproducer: https://syzkaller.appspot.com/text?tag=ReproC&x=1037a6b2880000
Kernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=e2021a61197ebe02
Dashboard link: https://syzkaller.appspot.com/bug?extid=a8e049cd3abd342936b6
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Debian
CVE-2022-49747: linux - In the Linux kernel, the following vulnerability has been resolved: erofs/zmap....
vendor_debian·2022·CVSS 5.5
CVE-2022-49747 [MEDIUM] CVE-2022-49747: linux - In the Linux kernel, the following vulnerability has been resolved: erofs/zmap....
In the Linux kernel, the following vulnerability has been resolved: erofs/zmap.c: Fix incorrect offset calculation Effective offset to add to length was being incorrectly calculated, which resulted in iomap->length being set to 0, triggering a WARN_ON in iomap_iter_done(). Fix that, and describe it in comments. This was reported as a crash by syzbot under an issue about a warning encountered in iomap_iter_done(), but unrelated to erofs. C reproducer: https://syzkaller.appspot.com/text?tag=ReproC&x=1037a6b2880000 Kernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=e2021a61197ebe02 Dashboard link: https://syzkaller.appspot.com/bug?extid=a8e049cd3abd342936b6
Scope: local
bookworm: resolved (fixed in 6.1.11-1)
bullseye: resolved
forky: resolved (fixed in 6.1.11-1)
sid: resolve
GHSA
GHSA-crqj-674f-vq27: In the Linux kernel, the following vulnerability has been resolved:
erofs/zmap
ghsa_unreviewed·2025-03-27
CVE-2022-49747 [MEDIUM] GHSA-crqj-674f-vq27: In the Linux kernel, the following vulnerability has been resolved:
erofs/zmap
In the Linux kernel, the following vulnerability has been resolved:
erofs/zmap.c: Fix incorrect offset calculation
Effective offset to add to length was being incorrectly calculated,
which resulted in iomap->length being set to 0, triggering a WARN_ON
in iomap_iter_done().
Fix that, and describe it in comments.
This was reported as a crash by syzbot under an issue about a warning
encountered in iomap_iter_done(), but unrelated to erofs.
C reproducer: https://syzkaller.appspot.com/text?tag=ReproC&x=1037a6b2880000
Kernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=e2021a61197ebe02
Dashboard link: https://syzkaller.appspot.com/bug?extid=a8e049cd3abd342936b6
OSV
CVE-2022-49747: In the Linux kernel, the following vulnerability has been resolved: erofs/zmap
osv·2025-03-27·CVSS 5.5
CVE-2022-49747 [MEDIUM] CVE-2022-49747: In the Linux kernel, the following vulnerability has been resolved: erofs/zmap
In the Linux kernel, the following vulnerability has been resolved: erofs/zmap.c: Fix incorrect offset calculation Effective offset to add to length was being incorrectly calculated, which resulted in iomap->length being set to 0, triggering a WARN_ON in iomap_iter_done(). Fix that, and describe it in comments. This was reported as a crash by syzbot under an issue about a warning encountered in iomap_iter_done(), but unrelated to erofs. C reproducer: https://syzkaller.appspot.com/text?tag=ReproC&x=1037a6b2880000 Kernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=e2021a61197ebe02 Dashboard link: https://syzkaller.appspot.com/bug?extid=a8e049cd3abd342936b6
No detection rules found.
No public exploits indexed.
2025-03-27
Published