PT-2025-8098 · Linux+1 · Linux Kernel+1
Wenqing Liu
·
Published
2022-03-03
·
Updated
2025-03-03
·
CVE-2022-49170
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.17-rc4 through 5.17-rc6
Description
The issue is related to an array-index-out-of-bounds error in the fs/f2fs/segment.c file. This occurs when mounting and operating a corrupted image, resulting in an out-of-bounds access on the sbi->block count[] array. The root cause is a missed sanity check on curseg->alloc type.
Recommendations
For Linux kernel versions 5.17-rc4 through 5.17-rc6, apply the fix to do a sanity check on curseg->alloc type to prevent the array-index-out-of-bounds error. As a temporary workaround, consider avoiding the use of corrupted images to minimize the risk of exploitation.
Exploit
Fix
Improper Validation of Array Index
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel