PT-2025-8204 · Linux+2 · Linux Kernel+2

Baokun Li

+1

·

Published

2025-02-26

·

Updated

2025-04-14

·

CVE-2022-49276

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue has been identified in the jffs2 file system. The leak occurs when an error is returned in jffs2 scan eraseblock() and some memory has been added to the jffs2 summary *s. This can lead to memory leaks, as observed in the kmemleak report. The issue is caused by the failure to release the memory added in s when an error occurs. To fix this, jffs2 sum reset collected(s) should be called on exit to release the memory. Additionally, a new tag "out buf" is added to prevent NULL pointer references.
Recommendations To resolve the issue, call jffs2 sum reset collected(s) on exit to release the memory added in s. As a temporary workaround, consider disabling the jffs2 scan medium() function until a patch is available. Restrict access to the jffs2 file system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-49276
OESA-2025-1317
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Suse