PT-2025-8003 · Linux+3 · Linux Kernel+3

Ethan Lien

·

Published

2022-03-07

·

Updated

2025-05-22

·

CVE-2022-49075

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, specifically in the btrfs file system. The issue arises from an overflow in the qgroup reserve limit when using the fallocate function to allocate a large range, exceeding 4GiB. This occurs because the bytes changed variable is set as an unsigned int, which overflows when dealing with large allocations. As a result, the qgroup limit is broken. The problem is demonstrated by a test script that attempts to fallocate files larger than the set qgroup limit, showing that the limit is indeed exceeded.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06049
CVE-2022-49075
SUSE-SU-2025:1176-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse