PT-2025-13280 · Linux+2 · Linux Kernel+2

Published

2025-03-27

·

Updated

2025-05-29

·

CVE-2022-49738

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.0-rc4-syzkaller-00362-gfef7fd48922d
Description A bug was found in the f2fs component of the Linux kernel, where a sanity check on i extra isize in the is alive() function was missing, resulting in a slab-out-of-bounds error. This issue was discovered by syzbot and is related to the gc data segment, is alive, data blkaddr, and do garbage collect functions. The root cause is the lack of a sanity check on i extra isize, leading to accessing an invalid address.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the sanity check on i extra isize in the is alive() function. As a temporary workaround, consider restricting access to the gc data segment function to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-06286
CVE-2022-49738

Affected Products

Astra Linux
Linux Kernel
Red Os