cbcvebase.
CVE-2022-49914
published 2025-05-01

CVE-2022-49914: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix inode list leak during backref walking at resolve_indirect_refs() During backref…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix inode list leak during backref walking at resolve_indirect_refs() During backref walking, at resolve_indirect_refs(), if we get an error we jump to the 'out' label and call ulist_free() on the 'parents' ulist, which frees all the elements in the ulist - however that does not free any inode lists that may be attached to elements, through the 'aux' field of a ulist node, so we end up leaking lists if we have any attached to the unodes. Fix this by calling free_leaf_list() instead of ulist_free() when we exit from resolve_indirect_refs(). The static function free_leaf_list() is moved up for this to be possible and it's slightly simplified by removing unnecessary code.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.8-1 (bookworm)linux 6.0.8-1 (bookworm)
linuxlinux
linuxlinux>= 3301958b7c1dae8f0f5ded63aa881e0b71e78464 < b1dc9019bb5f89abae85645de1a2dd4830c1f8e9b1dc9019bb5f89abae85645de1a2dd4830c1f8e9
linuxlinux>= 3301958b7c1dae8f0f5ded63aa881e0b71e78464 < cded2c89774b99b67c98147ae103ea878c92a206cded2c89774b99b67c98147ae103ea878c92a206
linuxlinux>= 3301958b7c1dae8f0f5ded63aa881e0b71e78464 < 2c0329406bb28109c07c6e23e5e3e0fa618a95d72c0329406bb28109c07c6e23e5e3e0fa618a95d7
linuxlinux>= 3301958b7c1dae8f0f5ded63aa881e0b71e78464 < a52e24c7fcc3c5ce3588a14e3663c00868d36623a52e24c7fcc3c5ce3588a14e3663c00868d36623
linuxlinux>= 3301958b7c1dae8f0f5ded63aa881e0b71e78464 < 6ba3479f9e96b9ad460c7e77abc26dd16e5dec4f6ba3479f9e96b9ad460c7e77abc26dd16e5dec4f
linuxlinux>= 3301958b7c1dae8f0f5ded63aa881e0b71e78464 < 396515db923ad5cbeb179d6b88927870b4cbebb7396515db923ad5cbeb179d6b88927870b4cbebb7
linuxlinux>= 3301958b7c1dae8f0f5ded63aa881e0b71e78464 < 5614dc3a47e3310fbc77ea3b67eaadd1c6417bf15614dc3a47e3310fbc77ea3b67eaadd1c6417bf1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 3.5 < 4.14.2994.14.299
linuxlinux_kernel>= 4.15 < 4.19.2654.19.265
linuxlinux_kernel>= 4.20 < 5.4.2245.4.224
linuxlinux_kernel>= 5.11 < 5.15.785.15.78
linuxlinux_kernel>= 5.16 < 6.0.86.0.8
linuxlinux_kernel>= 5.5 < 5.10.1545.10.154

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.