CVE-2022-49834
published 2025-05-01CVE-2022-49834: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix use-after-free bug of ns_writer on remount If a nilfs2 filesystem is downgraded…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
9.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix use-after-free bug of ns_writer on remount
If a nilfs2 filesystem is downgraded to read-only due to metadata
corruption on disk and is remounted read/write, or if emergency read-only
remount is performed, detaching a log writer and synchronizing the
filesystem can be done at the same time.
In these cases, use-after-free of the log writer (hereinafter
nilfs->ns_writer) can happen as shown in the scenario below:
Task1 Task2
-------------------------------- ------------------------------
nilfs_construct_segment
nilfs_segctor_sync
init_wait
init_waitqueue_entry
add_wait_queue
schedule
nilfs_remount (R/W remount case)
nilfs_attach_log_writer
nilfs_detach_log_writer
nilfs_segctor_destroy
kfree
finish_wait
_raw_spin_lock_irqsave
__raw_spin_lock_irqsave
do_raw_spin_lock
debug_spin_lock_before ns_writer is freed by Task2. After Task1
waked up, Task1 accesses nilfs->ns_writer which is already freed. This
scenario diagram is based on the Shigeru Yoshida's post [1].
This patch fixes the issue by not detaching nilfs->ns_writer on remount so
that this UAF race doesn't happen. Along with this change, this patch
also inserts a few necessary read-only checks with superblock instance
where only the ns_writer pointer was used to check if the filesystem is
read-only.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.10-1 (bookworm) | linux 6.0.10-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= fe5f171bb272946ce5fbf843ce2f8467d0d41b9a < b2fbf10040216ef5ee270773755fc2f5da65b749 | b2fbf10040216ef5ee270773755fc2f5da65b749 |
| linux | linux | >= fe5f171bb272946ce5fbf843ce2f8467d0d41b9a < 39a3ed68270b079c6b874d4e4727a512b9b4882c | 39a3ed68270b079c6b874d4e4727a512b9b4882c |
| linux | linux | >= fe5f171bb272946ce5fbf843ce2f8467d0d41b9a < b4736ab5542112fe0a40f140a0a0b072954f34da | b4736ab5542112fe0a40f140a0a0b072954f34da |
| linux | linux | >= fe5f171bb272946ce5fbf843ce2f8467d0d41b9a < 9b162e81045266a2d5b44df9dffdf05c54de9cca | 9b162e81045266a2d5b44df9dffdf05c54de9cca |
| linux | linux | >= fe5f171bb272946ce5fbf843ce2f8467d0d41b9a < 4feedde5486c07ea79787839153a71ca71329c7d | 4feedde5486c07ea79787839153a71ca71329c7d |
| linux | linux | >= fe5f171bb272946ce5fbf843ce2f8467d0d41b9a < afbd1188382a75f6cfe22c0b68533f7f9664f182 | afbd1188382a75f6cfe22c0b68533f7f9664f182 |
| linux | linux | >= fe5f171bb272946ce5fbf843ce2f8467d0d41b9a < b152300d5a1ba4258dacf9916bff20e6a8c7603b | b152300d5a1ba4258dacf9916bff20e6a8c7603b |
| linux | linux | >= fe5f171bb272946ce5fbf843ce2f8467d0d41b9a < 8cccf05fe857a18ee26e20d11a8455a73ffd4efd | 8cccf05fe857a18ee26e20d11a8455a73ffd4efd |
| linux | linux_kernel | < 4.9.334 | 4.9.334 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 4.10 < 4.14.300 | 4.14.300 |
| linux | linux_kernel | >= 4.15 < 4.19.267 | 4.19.267 |
| linux | linux_kernel | >= 4.20 < 5.4.225 | 5.4.225 |
| linux | linux_kernel | >= 5.11 < 5.15.79 | 5.15.79 |
| linux | linux_kernel | >= 5.16 < 6.0.9 | 6.0.9 |
| linux | linux_kernel | >= 5.5 < 5.10.155 | 5.10.155 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7jwj-6g7w-4c9q: In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix use-after-free bug of ns_writer on remount
If a nilfs2 filesystem is
ghsa_unreviewed·2025-05-01
CVE-2022-49834 [HIGH] CWE-416 GHSA-7jwj-6g7w-4c9q: In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix use-after-free bug of ns_writer on remount
If a nilfs2 filesystem is
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix use-after-free bug of ns_writer on remount
If a nilfs2 filesystem is downgraded to read-only due to metadata
corruption on disk and is remounted read/write, or if emergency read-only
remount is performed, detaching a log writer and synchronizing the
filesystem can be done at the same time.
In these cases, use-after-free of the log writer (hereinafter
nilfs->ns_writer) can happen as shown in the scenario below:
Task1 Task2
-------------------------------- ------------------------------
nilfs_construct_segment
nilfs_segctor_sync
init_wait
init_waitqueue_entry
add_wait_queue
schedule
nilfs_remount (R/W remount case)
nilfs_attach_log_writer
nilfs_detach_log_writer
nilfs_segctor_destroy
kfree
finish_wait
_raw_sp
OSV
CVE-2022-49834: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix use-after-free bug of ns_writer on remount If a nilfs2 filesystem is d
osv·2025-05-01·CVSS 7.8
CVE-2022-49834 [HIGH] CVE-2022-49834: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix use-after-free bug of ns_writer on remount If a nilfs2 filesystem is d
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix use-after-free bug of ns_writer on remount If a nilfs2 filesystem is downgraded to read-only due to metadata corruption on disk and is remounted read/write, or if emergency read-only remount is performed, detaching a log writer and synchronizing the filesystem can be done at the same time. In these cases, use-after-free of the log writer (hereinafter nilfs->ns_writer) can happen as shown in the scenario below: Task1 Task2 -------------------------------- ------------------------------ nilfs_construct_segment nilfs_segctor_sync init_wait init_waitqueue_entry add_wait_queue schedule nilfs_remount (R/W remount case) nilfs_attach_log_writer nilfs_detach_log_writer nilfs_segctor_destroy kfree finish_wait _raw_spin_l
Red Hat
kernel: nilfs2: fix use-after-free bug of ns_writer on remount
vendor_redhat·2025-05-01·CVSS 7.8
CVE-2022-49834 [HIGH] kernel: nilfs2: fix use-after-free bug of ns_writer on remount
kernel: nilfs2: fix use-after-free bug of ns_writer on remount
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix use-after-free bug of ns_writer on remount
If a nilfs2 filesystem is downgraded to read-only due to metadata
corruption on disk and is remounted read/write, or if emergency read-only
remount is performed, detaching a log writer and synchronizing the
filesystem can be done at the same time.
In these cases, use-after-free of the log writer (hereinafter
nilfs->ns_writer) can happen as shown in the scenario below:
Task1 Task2
-------------------------------- ------------------------------
nilfs_construct_segment
nilfs_segctor_sync
init_wait
init_waitqueue_entry
add_wait_queue
schedule
nilfs_remount (R/W remount case)
nilfs_attach_log_writer
nilfs_detac
Debian
CVE-2022-49834: linux - In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix...
vendor_debian·2022·CVSS 7.8
CVE-2022-49834 [HIGH] CVE-2022-49834: linux - In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix...
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix use-after-free bug of ns_writer on remount If a nilfs2 filesystem is downgraded to read-only due to metadata corruption on disk and is remounted read/write, or if emergency read-only remount is performed, detaching a log writer and synchronizing the filesystem can be done at the same time. In these cases, use-after-free of the log writer (hereinafter nilfs->ns_writer) can happen as shown in the scenario below: Task1 Task2 -------------------------------- ------------------------------ nilfs_construct_segment nilfs_segctor_sync init_wait init_waitqueue_entry add_wait_queue schedule nilfs_remount (R/W remount case) nilfs_attach_log_writer nilfs_detach_log_writer nilfs_segctor_destroy kfree finish_wait _raw_spin_l
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/39a3ed68270b079c6b874d4e4727a512b9b4882chttps://git.kernel.org/stable/c/4feedde5486c07ea79787839153a71ca71329c7dhttps://git.kernel.org/stable/c/8cccf05fe857a18ee26e20d11a8455a73ffd4efdhttps://git.kernel.org/stable/c/9b162e81045266a2d5b44df9dffdf05c54de9ccahttps://git.kernel.org/stable/c/afbd1188382a75f6cfe22c0b68533f7f9664f182https://git.kernel.org/stable/c/b152300d5a1ba4258dacf9916bff20e6a8c7603bhttps://git.kernel.org/stable/c/b2fbf10040216ef5ee270773755fc2f5da65b749https://git.kernel.org/stable/c/b4736ab5542112fe0a40f140a0a0b072954f34da
2025-05-01
Published